VYPR

Ipq8070 Firmware

by Qualcomm

CVEs (142)

  • CVE-2023-22387HigJul 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.

  • CVE-2021-35103HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible out of bound write due to improper validation of number of timer values received from firmware while syncing timers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired…

  • CVE-2021-35069HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2021-30303HigJan 3, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2020-11235HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2021-1915HigMay 7, 2021
    risk 0.51cvss 7.8epss 0.00

    Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2020-11289HigMay 7, 2021
    risk 0.51cvss 7.8epss 0.00

    Out of bound write can occur in TZ command handler due to lack of validation of command ID in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2020-11271HigFeb 22, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible out of bounds while accessing global control elements due to race condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon…

  • CVE-2020-11204HigFeb 22, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for parameters that are read from shared MSG RAM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…

  • CVE-2025-27066HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing an ANQP message.

  • CVE-2025-21448HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur while parsing SSID in action frames.

  • CVE-2024-33014HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing ESP IE from beacon/probe response frame.

  • CVE-2024-33012HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.

  • CVE-2024-33011HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.

  • CVE-2023-33105HigMar 4, 2024
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.

  • CVE-2023-43536HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parse fils IE with length equal to 1.

  • CVE-2023-43511HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.

  • CVE-2023-33116HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver.

  • CVE-2023-33109HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.

  • CVE-2023-33062HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing a BTM request.

Page 4 of 8