VYPR

Qca6436 Firmware

by Qualcomm

CVEs (629)

  • CVE-2023-21636MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption due to improper validation of array index in Linux while updating adn record.

  • CVE-2022-40524MedSep 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.

  • CVE-2023-28577MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel…

  • CVE-2023-28575MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.

  • CVE-2023-21650MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.

  • CVE-2023-21649MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in WLAN while running doDriverCmd for an unspecific command.

  • CVE-2023-21627MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Trusted Execution Environment while calling service API with invalid address.

  • CVE-2023-21638MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.

  • CVE-2023-21637MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Linux while calling system configuration APIs.

  • CVE-2023-21635MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.

  • CVE-2023-21633MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.

  • CVE-2023-21629MedJul 4, 2023
    risk 0.44cvss 6.8epss 0.00

    Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.

  • CVE-2022-33267MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Linux while sending DRM request.

  • CVE-2022-33227MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Linux android due to double free while calling unregister provider after register call.

  • CVE-2022-33302MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.

  • CVE-2022-33298MedApr 13, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to use after free in Modem while modem initialization.

  • CVE-2022-33289MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.

  • CVE-2022-33246MedFeb 12, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Audio due to use of out-of-range pointer offset while Initiating a voice call session from user space with invalid session id.

  • CVE-2022-33225MedFeb 12, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to use after free in trusted application environment.

  • CVE-2022-40519MedJan 9, 2023
    risk 0.44cvss 6.8epss 0.00

    Information disclosure due to buffer overread in Core

Page 27 of 32