Vulnerabilidades em Qualcomm, Inc.

2.934 resultados
Análise Vexday

Com 2.934 CVEs catalogadas, a Qualcomm apresenta um volume expressivo de vulnerabilidades, reflexo da amplitude de seu portfólio de chipsets e firmware embarcado. A taxa de exploração ativa — 12 entradas no catálogo KEV da CISA, ou 0,41% do total — está em linha com a média geral do catálogo, indicando que o risco de exploração confirmada não foge do padrão da indústria, embora 94 falhas de severidade crítica representem uma superfície de ataque relevante para equipes de segurança que dependem de componentes Qualcomm em ambientes móveis, automotivos ou de IoT. A CVE mais perigosa atualmente em exploração ativa, CVE-2020-11261, apresenta EPSS de 0,0177, sugerindo probabilidade de exploração adicional relativamente baixa no curto prazo, mas sua presença no KEV exige atenção imediata em qualquer inventário de ativos afetados. O surgimento de 49 novas CVEs nos últimos 90 dias e a disponibilidade de PoCs públicas para 3 vulnerabilidades reforçam a necessidade de ciclos contínuos de atualização de firmware e monitoramento ativo de patches liberados pelo fabricante.

CVE-2014-9928In GERAN in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentialEPSS 0.5%CVE-2014-9926In GNSS in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.EPSS 0.5%CVE-2024-45569CRITICALImproper Validation of Array Index in WLAN Host CommunicationEPSS 0.5%CVE-2017-11092In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the KGSL driver function EPSS 0.5%CVE-2017-8253In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel memory can potentially be overwritten if an invalid mEPSS 0.5%CVE-2017-8263In all Qualcomm products with Android releases from CAF using the Linux kernel, a kernel fault can occur when doing certain operations on a EPSS 0.5%CVE-2015-9007In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exist.EPSS 0.5%CVE-2014-9949In TrustZone in all Android releases from CAF using the Linux kernel, an Untrusted Pointer Dereference vulnerability could potentially existEPSS 0.5%CVE-2014-9930In WCDMA in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.EPSS 0.5%CVE-2014-9924In 1x in all Android releases from CAF using the Linux kernel, a Signed to Unsigned Conversion Error could potentially occur.EPSS 0.5%CVE-2014-9948In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Validation of Array Index vulnerability could potentially EPSS 0.5%CVE-2014-9946In Core Kernel in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.EPSS 0.5%CVE-2014-9923In NAS in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentiallyEPSS 0.5%CVE-2014-9942In Boot in all Android releases from CAF using the Linux kernel, a Use of Uninitialized Variable vulnerability could potentially exist.EPSS 0.5%CVE-2022-25719HIGHInformation disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon ConnectEPSS 0.5%CVE-2017-8259In the service locator in all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow can occur as the vaEPSS 0.5%CVE-2017-7369In all Android releases from CAF using the Linux kernel, an array index in an ALSA routine is not properly validating potentially leading toEPSS 0.5%CVE-2016-5854In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, kernel heap memory can be exposed to userspacEPSS 0.5%CVE-2016-5855In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a user-supplied buffer is casted to a structuEPSS 0.5%CVE-2017-9681In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if EPSS 0.5%