Записи qualcomm
2 538 опубликованных записей вендора qualcomm.
Профиль для исследователя
- Попали в KEV
- 13 · 0,5 %
- С эксплойтом
- 14 · 0,6 %
- Pre-auth RCE
- 23
- С записью об исправлении
- 0,2 %
- Медиана: публикация → KEV
- 1 дн.
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')238
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer232
- CWE-416 Use After Free232
- CWE-126 Buffer Over-read205
- CWE-125 Out-of-bounds Read174
- CWE-20 Improper Input Validation161
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
2 538 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2025-21479Готовый эксплойт | Incorrect Authorization in Graphicsqualcomm · aqt1000 firmware · CWE-863 | Высокая8,6 | KEV | 0,8 % | 3 июн. 2025 г. |
64На этой неделе | CVE-2025-21480Готовый эксплойт | Incorrect Authorization in Graphics Windowsqualcomm · aqt1000 firmware · CWE-863 | Высокая8,6 | KEV | 0,5 % | 3 июн. 2025 г. |
62На этой неделе | CVE-2013-2596Готовый эксплойт | Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Alinux · linux kernel · CWE-190 | Высокая7,8 | KEV | 3,2 % | 12 апр. 2013 г. |
61На этой неделе | CVE-2020-11261Готовый эксплойт | Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, qualcomm · apq8009 firmware · CWE-787 | Высокая7,8 | KEV | 1,6 % | 9 июн. 2021 г. |
61На этой неделе | CVE-2021-1905Готовый эксплойт | Possible use after free due to improper handling of memory mapping of multiple processes simultaneously.qualcomm · apq8009 firmware · CWE-416 | Высокая7,8 | KEV | 1,5 % | 7 мая 2021 г. |
61На этой неделе | CVE-2026-21385Готовый эксплойт | Integer Overflow or Wraparound in Graphicsqualcomm · sm7675p firmware · CWE-190 | Высокая7,8 | KEV | 1,3 % | 2 мар. 2026 г. |
61На этой неделе | CVE-2023-33106Готовый эксплойт | Use of Out-of-range Pointer Offset in Graphicsqualcomm · ar8035 firmware · CWE-823 | Высокая7,8 | KEV | 0,9 % | 4 дек. 2023 г. |
61На этой неделе | CVE-2023-33107Готовый эксплойт | Integer Overflow or Wraparound in Graphics Linuxqualcomm · 315 5g iot modem firmware · CWE-190 | Высокая7,8 | KEV | 0,9 % | 4 дек. 2023 г. |
61На этой неделе | CVE-2023-33063Готовый эксплойт | Use After Free in DSP Servicesqualcomm · 315 5g iot modem firmware · CWE-416 | Высокая7,8 | KEV | 0,7 % | 4 дек. 2023 г. |
61На этой неделе | CVE-2024-43047Готовый эксплойт | Use After Free in DSP Servicequalcomm · fastconnect 6700 firmware · CWE-416 | Высокая7,8 | KEV | 0,7 % | 7 окт. 2024 г. |
61На этой неделе | CVE-2022-22071Готовый эксплойт | Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Aqualcomm · apq8053 firmware · CWE-416 | Высокая7,8 | KEV | 0,5 % | 14 июн. 2022 г. |
60На этой неделе | CVE-2025-27038Готовый эксплойт | Use After Free in Graphicsqualcomm · ar8031 firmware · CWE-416 | Высокая7,5 | KEV | 1,0 % | 3 июн. 2025 г. |
52В плане | CVE-2021-1906Готовый эксплойт | Improper handling of address deregistration on failure can lead to new GPU address allocation failure.qualcomm · apq8009 firmware | Средняя5,5 | KEV | 0,5 % | 7 мая 2021 г. |
50В плане | CVE-2005-4267Готовый эксплойт | Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP command that ends wiqualcomm · worldmail · CWE-119 | Высокая7,5 | — | 66,8 % | 21 дек. 2005 г. |
48В плане | CVE-2020-3657Эксплойта нет | u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client thqualcomm · apq8009 firmware · CWE-120 | Критическая9,8 | — | 28,3 % | 2 нояб. 2020 г. |
45В плане | CVE-2020-11117Эксплойта нет | u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulqualcomm · ipq4019 firmware · CWE-77 | Критическая9,8 | — | 19,7 % | 8 сент. 2020 г. |
43В плане | CVE-2020-11264Эксплойта нет | Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdqualcomm · apq8053 firmware · CWE-287 | Критическая9,8 | — | 13,2 % | 8 сент. 2021 г. |
43В плане | CVE-1999-0006Proof of concept | Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.qualcomm · qpopper · CWE-125 | Критическая9,8 | — | 12,1 % | 14 июл. 1998 г. |
43В плане | CVE-2003-0143Proof of concept | The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allowqualcomm · qpopper | Критическая10,0 | — | 8,6 % | 18 мар. 2003 г. |
41В плане | CVE-1999-0822Proof of concept | Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.qualcomm · qpopper | Критическая10,0 | — | 4,9 % | 30 нояб. 1999 г. |
41В плане | CVE-2001-1046Эксплойта нет | Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.qualcomm · qpopper | Критическая10,0 | — | 1,9 % | 2 июн. 2001 г. |
40В плане | CVE-2021-30351Эксплойта нет | An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Autoqualcomm · apq8009 firmware · CWE-120 | Критическая9,8 | — | 4,0 % | 3 янв. 2022 г. |
40В плане | CVE-2021-1965Proof of concept | Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdragoqualcomm · aqt1000 firmware · CWE-20 | Критическая9,8 | — | 3,0 % | 13 июл. 2021 г. |
40В плане | CVE-2020-11153Эксплойта нет | u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to remote code execution'qualcomm · apq8053 firmware · CWE-787 | Критическая9,8 | — | 2,3 % | 2 нояб. 2020 г. |
40В плане | CVE-2017-14911Эксплойта нет | In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SDqualcomm · mdm9206 firmware · CWE-287 | Критическая9,8 | — | 2,2 % | 30 мар. 2018 г. |
- CVE-2025-2147964На этой неделе
Incorrect Authorization in Graphics
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 1 %qualcomm · aqt1000 firmware3 июн. 2025 г.
- CVE-2025-2148064На этой неделе
Incorrect Authorization in Graphics Windows
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 0 %qualcomm · aqt1000 firmware3 июн. 2025 г.
- CVE-2013-259662На этой неделе
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of A
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 3 %linux · linux kernel12 апр. 2013 г.
- CVE-2020-1126161На этой неделе
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto,
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 2 %qualcomm · apq8009 firmware9 июн. 2021 г.
- CVE-2021-190561На этой неделе
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously.
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 2 %qualcomm · apq8009 firmware7 мая 2021 г.
- CVE-2026-2138561На этой неделе
Integer Overflow or Wraparound in Graphics
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 1 %qualcomm · sm7675p firmware2 мар. 2026 г.
- CVE-2023-3310661На этой неделе
Use of Out-of-range Pointer Offset in Graphics
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 1 %qualcomm · ar8035 firmware4 дек. 2023 г.
- CVE-2023-3310761На этой неделе
Integer Overflow or Wraparound in Graphics Linux
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 1 %qualcomm · 315 5g iot modem firmware4 дек. 2023 г.
- CVE-2023-3306361На этой неделе
Use After Free in DSP Services
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 1 %qualcomm · 315 5g iot modem firmware4 дек. 2023 г.
- CVE-2024-4304761На этой неделе
Use After Free in DSP Service
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 1 %qualcomm · fastconnect 6700 firmware7 окт. 2024 г.
- CVE-2022-2207161На этой неделе
Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon A
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 0 %qualcomm · apq8053 firmware14 июн. 2022 г.
- CVE-2025-2703860На этой неделе
Use After Free in Graphics
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 1 %qualcomm · ar8031 firmware3 июн. 2025 г.
- CVE-2021-190652В плане
Improper handling of address deregistration on failure can lead to new GPU address allocation failure.
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 1 %qualcomm · apq8009 firmware7 мая 2021 г.
- CVE-2005-426750В плане
Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP command that ends wi
ВысокаяCVSS 7,5Готовый эксплойтEPSS 67 %qualcomm · worldmail21 дек. 2005 г.
- CVE-2020-365748В плане
u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from a tethered client th
КритическаяCVSS 9,8Эксплойта нетEPSS 28 %qualcomm · apq8009 firmware2 нояб. 2020 г.
- CVE-2020-1111745В плане
u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resul
КритическаяCVSS 9,8Эксплойта нетEPSS 20 %qualcomm · ipq4019 firmware8 сент. 2020 г.
- CVE-2020-1126443В плане
Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapd
КритическаяCVSS 9,8Эксплойта нетEPSS 13 %qualcomm · apq8053 firmware8 сент. 2021 г.
- CVE-1999-000643В плане
Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.
КритическаяCVSS 9,8Proof of conceptEPSS 12 %qualcomm · qpopper14 июл. 1998 г.
- CVE-2003-014343В плане
The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow
КритическаяCVSS 10,0Proof of conceptEPSS 9 %qualcomm · qpopper18 мар. 2003 г.
- CVE-1999-082241В плане
Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.
КритическаяCVSS 10,0Proof of conceptEPSS 5 %qualcomm · qpopper30 нояб. 1999 г.
- CVE-2001-104641В плане
Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %qualcomm · qpopper2 июн. 2001 г.
- CVE-2021-3035140В плане
An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %qualcomm · apq8009 firmware3 янв. 2022 г.
- CVE-2021-196540В плане
Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdrago
КритическаяCVSS 9,8Proof of conceptEPSS 3 %qualcomm · aqt1000 firmware13 июл. 2021 г.
- CVE-2020-1115340В плане
u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to remote code execution'
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %qualcomm · apq8053 firmware2 нояб. 2020 г.
- CVE-2017-1491140В плане
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %qualcomm · mdm9206 firmware30 мар. 2018 г.