Vulnerabilidades em Qualcomm, Inc.

2.934 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2023-21671CRITICALImproper Input Validation in CoreEPSS 0.1%CVE-2021-1898MEDIUMPossible buffer over-read due to incorrect overflow check when loading splash image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, SEPSS 0.1%CVE-2021-1901MEDIUMPossible buffer over-read due to lack of length check while flashing meta images in Snapdragon Consumer IOT, Snapdragon Industrial IOT, SnapEPSS 0.1%CVE-2021-1918MEDIUMImproper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon IndustrEPSS 0.1%CVE-2024-45555HIGHInteger Overflow to Buffer Overflow in Automotive OS PlatformEPSS 0.1%CVE-2021-1897MEDIUMPossible Buffer Over-read due to lack of validation of boundary checks when loading splash image in Snapdragon Consumer IOT, Snapdragon InduEPSS 0.1%CVE-2022-25743HIGHMemory corruption in graphics due to use-after-free while importing graphics buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon ConneEPSS 0.1%CVE-2018-12010In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Absence of length sanity check maEPSS 0.1%CVE-2023-33070HIGHImproper Authentication in Automotive OSEPSS 0.1%CVE-2023-33055HIGHBuffer Copy Without Checking Size of Input in AudioEPSS 0.1%CVE-2018-11988In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Un-trusted pointer de-reference iEPSS 0.1%CVE-2022-33242HIGHImproper authentication in Qualcomm IPCEPSS 0.1%CVE-2018-12006In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Users with no extra privileges caEPSS 0.1%CVE-2018-12011In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket addEPSS 0.1%CVE-2023-22668MEDIUMUse After Free in AudioEPSS 0.1%CVE-2019-2260A race condition occurs while processing perf-event which can lead to a use after free condition in Snapdragon Auto, Snapdragon Compute, SnaEPSS 0.1%CVE-2023-28545HIGHImproper Restriction of Operations within the Bounds of a Memory Buffer in TZ Secure OSEPSS 0.1%CVE-2019-14070Possible use after free issue in pcm volume controls due to race condition exist in private data used in mixer controls in Snapdragon Auto, EPSS 0.1%CVE-2021-30333HIGHImproper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon CoEPSS 0.1%CVE-2023-28570MEDIUMBuffer Copy without Checking Size of Input in AudioEPSS 0.1%