Vulnerabilidades em Qualcomm, Inc.

2.934 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2015-9040In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in a GERAN API.EPSS 0.8%CVE-2016-10382In all Qualcomm products with Android releases from CAF using the Linux kernel, access control to the I2C bus is not sufficient.EPSS 0.8%CVE-2015-9047In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GNSS when performing a scan after EPSS 0.8%CVE-2025-27038HIGHUse After Free in GraphicsEPSS 0.8%KEVCVE-2022-25651CRITICALMemory corruption in bluetooth host due to integer overflow while processing BT HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOTEPSS 0.8%CVE-2020-11159Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer beinEPSS 0.8%CVE-2018-11291In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074, MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6564, QCA6EPSS 0.8%CVE-2020-11134Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like NAN ranging setup atEPSS 0.8%CVE-2020-11126Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon Compute, EPSS 0.8%CVE-2019-14012Possibility of null pointer deference as the array of video codecs from media info is referenced without null checking while processing SDP EPSS 0.8%CVE-2019-14061Null-pointer dereference can occur while accessing the segment element info when it is not allocated and assigned in Snapdragon Auto, SnapdrEPSS 0.8%CVE-2019-10591Null pointer dereference can happen when parsing udta atom which is non-standard and having invalid depth in Snapdragon Auto, Snapdragon ComEPSS 0.8%CVE-2019-10549Null pointer dereference issue can happen due to improper validation of CSEQ header response received from network in Snapdragon Auto, SnapdEPSS 0.8%CVE-2019-14022Error occurs While extracting the ipv6_header having an invalid length due to lack of length check in Snapdragon Auto, Snapdragon Compute, SEPSS 0.8%CVE-2017-6211In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the processing of a downlEPSS 0.8%CVE-2016-5853In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length vEPSS 0.8%CVE-2021-1972CRITICALPossible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon ConEPSS 0.8%CVE-2018-5875While parsing an mp4 file, an integer overflow leading to a buffer overflow can occur in Snapdragon Automobile, Snapdragon Mobile and SnapdrEPSS 0.8%CVE-2020-11139Out of bound memory access while processing frames due to lack of check of invalid frames received in Snapdragon Auto, Snapdragon Compute, SEPSS 0.8%CVE-2020-11214Buffer over-read while processing NDL attribute if attribute length is larger than expected and then FW is treating it as more number of immEPSS 0.8%