VYPR

Qca6426 Firmware

by Qualcomm

CVEs (412)

  • CVE-2020-11227CriMar 17, 2021
    risk 0.64cvss 9.8epss 0.01

    Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…

  • CVE-2020-11192CriMar 17, 2021
    risk 0.64cvss 9.8epss 0.01

    Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2020-11272CriFeb 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version later can lead to use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics…

  • CVE-2020-11170CriFeb 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…

  • CVE-2020-11163CriFeb 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters received from the ePDG server in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2020-11261HigKEVJun 9, 2021
    risk 0.63cvss 7.8epss 0.02

    Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2021-30317CriFeb 11, 2022
    risk 0.61cvss 9.3epss 0.01

    Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2023-43538CriJun 3, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.

  • CVE-2023-28578CriMar 4, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core Services while executing the command for removing a single event listener.

  • CVE-2023-33072CriFeb 6, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core while processing control functions.

  • CVE-2023-33030CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in HLOS while running playready use-case.

  • CVE-2023-21651CriAug 8, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.

  • CVE-2021-30285CriJan 13, 2022
    risk 0.60cvss 9.3epss 0.00

    Improper validation of memory region in Hypervisor can lead to incorrect region mapping in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-30276CriJan 3, 2022
    risk 0.60cvss 9.3epss 0.00

    Improper access control while doing XPU re-configuration dynamically can lead to unauthorized access to a secure resource in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-30275CriJan 3, 2022
    risk 0.60cvss 9.3epss 0.00

    Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2020-11301CriSep 8, 2021
    risk 0.60cvss 9.1epss 0.11

    Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

  • CVE-2020-11264CriSep 8, 2021
    risk 0.60cvss 9.1epss 0.13

    Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon…

  • CVE-2023-33054CriDec 5, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.

  • CVE-2023-28540CriOct 3, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in Data Modem due to improper authentication during TLS handshake.

  • CVE-2021-30343CriJun 14, 2022
    risk 0.59cvss 9.1epss 0.00

    Improper integrity check can lead to race condition between tasks PDCP and RRC? after a valid RRC Command packet has been received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

Page 2 of 21