VYPR

Sd855 Firmware

by Qualcomm

CVEs (527)

  • CVE-2021-1969MedOct 20, 2021
    risk 0.40cvss 6.2epss 0.00

    Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice…

  • CVE-2021-1968MedOct 20, 2021
    risk 0.40cvss 6.2epss 0.00

    Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice…

  • CVE-2021-1929MedSep 8, 2021
    risk 0.40cvss 6.2epss 0.00

    Lack of strict validation of bootmode can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-1904MedSep 8, 2021
    risk 0.40cvss 6.2epss 0.01

    Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2023-28586MedDec 5, 2023
    risk 0.39cvss 6.0epss 0.00

    Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.

  • CVE-2020-3664MedFeb 22, 2021
    risk 0.39cvss 6.0epss 0.00

    Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2023-43530MedMay 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Memory corruption in HLOS while checking for the storage type.

  • CVE-2023-33076MedFeb 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

  • CVE-2022-33296MedApr 13, 2023
    risk 0.38cvss 5.9epss 0.00

    Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.

  • CVE-2022-33260MedMar 10, 2023
    risk 0.38cvss 5.9epss 0.00

    Memory corruption due to stack based buffer overflow in core while sending command from USB of large size.

  • CVE-2022-33266MedJan 9, 2023
    risk 0.38cvss 5.9epss 0.00

    Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content.

  • CVE-2020-11294MedMay 7, 2021
    risk 0.38cvss 5.9epss 0.00

    Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2024-43046MedApr 7, 2025
    risk 0.36cvss 5.5epss 0.00

    There may be information disclosure during memory re-allocation in TZ Secure OS.

  • CVE-2024-43056MedMar 3, 2025
    risk 0.36cvss 5.5epss 0.00

    Transient DOS during hypervisor virtual I/O operation in a virtual machine.

  • CVE-2024-33043MedSep 2, 2024
    risk 0.36cvss 5.5epss 0.00

    Transient DOS while handling PS event when Program Service name length offset value is set to 255.

  • CVE-2023-33064MedFeb 6, 2024
    risk 0.36cvss 5.5epss 0.00

    Transient DOS in Audio when invoking callback function of ASM driver.

  • CVE-2022-25675MedDec 13, 2022
    risk 0.36cvss 5.5epss 0.00

    Denial of service due to reachable assertion in modem while processing filter rule from application client in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35119MedJun 14, 2022
    risk 0.36cvss 5.5epss 0.00

    Potential out of Bounds read in FIPS event processing due to improper validation of the length from the firmware in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2020-11221MedMar 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon…

  • CVE-2020-11199MedMar 17, 2021
    risk 0.36cvss 5.5epss 0.00

    HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…

Page 26 of 27