Vulnerabilidades em Qualcomm, Inc.

2.934 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2021-30350HIGHLack of MBN header size verification against input buffer can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon CEPSS 0.2%CVE-2021-1932HIGHImproper access control in trusted application environment can cause unauthorized access to CDSP or ADSP VM memory with either privilege in EPSS 0.2%CVE-2021-30281HIGHPossible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configurationEPSS 0.2%CVE-2017-11035In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, possible buffer overflow or EPSS 0.2%CVE-2021-35129HIGHMemory corruption in BT controller due to improper length check while processing vendor specific commands in Snapdragon Compute, Snapdragon EPSS 0.2%CVE-2021-35091HIGHPossible out of bounds read due to improper typecasting while handling page fault for global memory in Snapdragon Connectivity, Snapdragon MEPSS 0.2%CVE-2021-30349HIGHImproper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapdragon Auto, SnapdragEPSS 0.2%CVE-2021-35130HIGHMemory corruption in graphics support layer due to use after free condition in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon IndustriEPSS 0.2%CVE-2021-1913HIGHPossible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon Compute, EPSS 0.2%CVE-2023-33088HIGHNULL pointer dereference in WLAN FirmwareEPSS 0.2%CVE-2023-33092HIGHBuffer Copy Without Checking Size of Input in Bluetooth HOSTEPSS 0.2%CVE-2021-30334HIGHPossible use after free due to lack of null check of DRM file status after file structure is freed in Snapdragon Auto, Snapdragon Compute, SEPSS 0.2%CVE-2023-33022HIGHInteger Overflow to Buffer Overflow in HLOSEPSS 0.2%CVE-2017-14897In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while handling the QSEOS_RPMEPSS 0.2%CVE-2021-30338HIGHImproper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon ComputeEPSS 0.2%CVE-2017-9716In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the qbt1000 driver implementEPSS 0.2%CVE-2017-11017In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a specially cEPSS 0.2%CVE-2021-1909HIGHBuffer overflow occurs in trusted applications due to lack of length check of parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon EPSS 0.2%CVE-2018-5825In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security pEPSS 0.2%CVE-2020-11284HIGHLocked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the memory region untrusteEPSS 0.2%