What is the qualcomm CNA?
qualcomm is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 2,958 CVE records since 2017.
How many CVEs has qualcomm published?
qualcomm has published 2,958 CVE records, including 509 in the last two years.
What is qualcomm's CVE data quality grade?
RadicalNotion.AI grades qualcomm's CVE data quality as D, with an overall completeness score of 66.6%. This reflects how consistently its CVE records include vendor (95.8%), product (95.8%), CVSS (43.1%), and CWE (31.7%) information.
What products does qualcomm publish CVEs for?
qualcomm most frequently publishes CVEs for WCD9380, wcd9380 firmware, WSA8830, WSA8835, WCD9385.
Which vendors does qualcomm cover?
qualcomm publishes CVEs across 4 distinct vendors, most often Qualcomm, Inc., qualcomm, google, Qualcomm Technologies, Inc., debian.
Is qualcomm actively publishing CVEs?
qualcomm is currently active, based on 509 CVEs in the last two years.
What is the average severity of qualcomm's CVEs?
The average CVSS base score across qualcomm's scored CVEs is 7.7.
How many critical CVEs has qualcomm published?
qualcomm has published 97 critical-severity CVEs and 943 high-severity CVEs.
Are any of qualcomm's CVEs in CISA's Known Exploited Vulnerabilities catalog?
Yes. 12 of qualcomm's CVEs are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, meaning they are confirmed to be exploited in the wild.
What are the most common weakness types in qualcomm's CVEs?
qualcomm's CVEs most often map to these CWE weakness types: CWE-126 (Buffer Over-read), CWE-416 (Use After Free), CWE-120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')), CWE-20 (Improper Input Validation).
How does qualcomm rank among CNAs?
By total CVE volume, qualcomm ranks #21 of 370 CNAs, and it reports more complete CVE records than 17% of all CNAs.