VYPR

Sd855 Firmware

by Qualcomm

CVEs (374)

  • CVE-2020-11192CriMar 17, 2021
    risk 0.64cvss 9.8epss 0.01

    Out of bound write while parsing SDP string due to missing check on null termination in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2020-11272CriFeb 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version later can lead to use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics…

  • CVE-2020-11170CriFeb 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…

  • CVE-2020-11163CriFeb 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters received from the ePDG server in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2018-11271CriMay 24, 2019
    risk 0.64cvss 9.8epss 0.01

    Improper authentication can happen on Remote command handling due to inappropriate handling of events in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in…

  • CVE-2020-11261HigKEVJun 9, 2021
    risk 0.63cvss 7.8epss 0.02

    Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2021-30317CriFeb 11, 2022
    risk 0.61cvss 9.3epss 0.01

    Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2023-43538CriJun 3, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.

  • CVE-2023-28578CriMar 4, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core Services while executing the command for removing a single event listener.

  • CVE-2023-33072CriFeb 6, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core while processing control functions.

  • CVE-2023-33032CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

  • CVE-2023-33030CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in HLOS while running playready use-case.

  • CVE-2023-21651CriAug 8, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.

  • CVE-2020-11301CriSep 8, 2021
    risk 0.60cvss 9.1epss 0.11

    Improper authentication of un-encrypted plaintext Wi-Fi frames in an encrypted network can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

  • CVE-2020-11264CriSep 8, 2021
    risk 0.60cvss 9.1epss 0.13

    Improper authentication of Non-EAPOL/WAPI plaintext frames during four-way handshake can lead to arbitrary network packet injection in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon…

  • CVE-2023-33054CriDec 5, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.

  • CVE-2023-28540CriOct 3, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in Data Modem due to improper authentication during TLS handshake.

  • CVE-2020-11159CriJun 9, 2021
    risk 0.59cvss 9.1epss 0.01

    Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon…

  • CVE-2020-11126CriJun 9, 2021
    risk 0.59cvss 9.1epss 0.01

    Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2020-11222CriMar 17, 2021
    risk 0.59cvss 9.1epss 0.01

    Buffer over read while processing MT SMS with maximum length due to improper length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile

Page 2 of 19