VYPR

Qca6390 Firmware

by Qualcomm

CVEs (478)

  • CVE-2020-11252HigApr 7, 2021
    risk 0.47cvss 7.2epss 0.00

    Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2023-21626HigAug 8, 2023
    risk 0.46cvss 7.1epss 0.00

    Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.

  • CVE-2022-40529HigJun 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Memory corruption due to improper access control in kernel while processing a mapping request from root process.

  • CVE-2022-40523HigJun 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Information disclosure in Kernel due to indirect branch misprediction.

  • CVE-2022-22076HigJun 6, 2023
    risk 0.46cvss 7.1epss 0.00

    information disclosure due to cryptographic issue in Core during RPMB read request.

  • CVE-2021-35101HigJun 14, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile

  • CVE-2021-30278HigJan 3, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and…

  • CVE-2021-1894HigJan 3, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and…

  • CVE-2021-1935HigSep 9, 2021
    risk 0.46cvss 7.1epss 0.00

    Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon…

  • CVE-2020-11262HigJun 9, 2021
    risk 0.46cvss 7.0epss 0.00

    A race between command submission and destroying the context can cause an invalid context being added to the list leads to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2020-11250HigJun 9, 2021
    risk 0.46cvss 7.0epss 0.00

    Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon…

  • CVE-2020-11161HigJun 9, 2021
    risk 0.46cvss 7.1epss 0.00

    Out-of-bounds memory access can occur while calculating alignment requirements for a negative width from external components in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2020-11290HigMar 17, 2021
    risk 0.46cvss 7.0epss 0.00

    Use after free condition in msm ioctl events due to race between the ioctl register and deregister events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2020-11173HigNov 2, 2020
    risk 0.46cvss 7.0epss 0.00

    u'Two threads running simultaneously from user space can lead to race condition in fastRPC driver' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-30299MedNov 22, 2024
    risk 0.44cvss 6.7epss 0.00

    Possible out of bound access in audio module due to lack of validation of user provided input.

  • CVE-2023-33024MedDec 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption while sending SMS from AP firmware.

  • CVE-2023-21654MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Audio during playback session with audio effects enabled.

  • CVE-2023-21644MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.

  • CVE-2023-21636MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption due to improper validation of array index in Linux while updating adn record.

  • CVE-2022-40524MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.

Page 20 of 24