VYPR

Snapdragon Auto

by Qualcomm

CVEs (78)

  • CVE-2021-35115HigApr 1, 2022
    risk 0.55cvss 8.4epss 0.00

    Improper handling of multiple session supported by PVM backend can lead to use after free in Snapdragon Auto, Snapdragon Mobile

  • CVE-2021-35089HigApr 1, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible buffer overflow due to lack of input IB amount validation while processing the user command in Snapdragon Auto

  • CVE-2021-30315HigOct 20, 2021
    risk 0.55cvss 8.4epss 0.00

    Improper handling of sensor HAL structure in absence of sensor can lead to use after free in Snapdragon Auto

  • CVE-2021-30306HigOct 20, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible buffer over read due to improper buffer allocation for file length passed from user space in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30305HigOct 20, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible out of bound access due to lack of validation of page offset before page is inserted in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30292HigOct 20, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible memory corruption due to lack of validation of client data used for memory allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

  • CVE-2021-1932HigOct 20, 2021
    risk 0.55cvss 8.4epss 0.00

    Improper access control in trusted application environment can cause unauthorized access to CDSP or ADSP VM memory with either privilege in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2021-30261HigSep 17, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-30290HigSep 9, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible null pointer dereference due to race condition between timeline fence signal and time line fence destroy in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35117HigApr 1, 2022
    risk 0.53cvss 8.2epss 0.01

    An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2019-10510HigSep 30, 2019
    risk 0.53cvss 8.2epss 0.01

    BT process died and BT toggled due to null pointer dereference when invalid vendor pass through command sent from remote in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS405, QCS605, SD 636, SD 675, SD 730, SD 820A, SD 835, SD 845 /…

  • CVE-2022-22103HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in multimedia driver due to double free while processing data from user in Snapdragon Auto

  • CVE-2021-35102HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to lack of validation for the length of NAI string read from EFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2021-35094HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2020-11187HigFeb 22, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible memory corruption in BSI module due to improper validation of parameter count in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2020-11120HigSep 8, 2020
    risk 0.51cvss 7.8epss 0.00

    u'Calling thread may free the data buffer pointer that was passed to the callback and later when event loop executes the callback, data buffer may not be valid and will lead to use after free scenario' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon…

  • CVE-2019-14089HigSep 8, 2020
    risk 0.51cvss 7.8epss 0.00

    u'Keymaster attestation key and device IDs provisioning which is a one time process is incorrectly allowed to be re-provisioned after a user data erase or a factory reset' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2019-14091HigJun 22, 2020
    risk 0.51cvss 7.8epss 0.00

    Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, QCS405, Rennell, Saipan, SC8180X, SDX55,…

  • CVE-2020-3625HigJun 2, 2020
    risk 0.51cvss 7.8epss 0.00

    When making query to DSP capabilities, Stack out of bounds occurs due to wrong buffer length configured for DSP attributes in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in SM8250, SXR2130

  • CVE-2019-14122HigApr 16, 2020
    risk 0.51cvss 7.8epss 0.00

    Memory failure in SKB if it fails to to add the requested padding to the skb in low memory targets or targets with major memory fragmentation in Snapdragon Auto, Snapdragon Mobile in Saipan, SM8150, SM8250, SXR2130