VYPR

HLOS

by Qualcomm

CVEs (15)

  • CVE-2024-43047HigKEVOct 7, 2024
    risk 0.63cvss 7.8epss 0.01

    Memory corruption while maintaining memory maps of HLOS memory.

  • CVE-2023-33030CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in HLOS while running playready use-case.

  • CVE-2023-33022HigDec 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in HLOS while invoking IOCTL calls from user-space.

  • CVE-2023-24853HigOct 3, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory Corruption in HLOS while registering for key provisioning notify.

  • CVE-2024-53010HigJun 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption may occur while attaching VM when the HLOS retains access to VM.

  • CVE-2024-23356HigAug 5, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption during session sign renewal request calls in HLOS.

  • CVE-2023-43513HigFeb 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.

  • CVE-2023-33117HigJan 2, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command.

  • CVE-2022-33278HigMar 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.

  • CVE-2023-21652HigAug 8, 2023
    risk 0.50cvss 7.7epss 0.00

    Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.

  • CVE-2023-28556HigNov 7, 2023
    risk 0.46cvss 7.1epss 0.00

    Cryptographic issue in HLOS during key management.

  • CVE-2023-21626HigAug 8, 2023
    risk 0.46cvss 7.1epss 0.00

    Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.

  • CVE-2023-33077MedFeb 6, 2024
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in HLOS while converting from authorization token to HIDL vector.

  • CVE-2023-43515MedApr 1, 2024
    risk 0.43cvss 6.6epss 0.00

    Memory corruption in HLOS while running kernel address sanitizers (syzkaller) on tmecom with DEBUG_FS enabled.

  • CVE-2023-43530MedMay 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Memory corruption in HLOS while checking for the storage type.