VYPR

Msm8909w Firmware

by Qualcomm

CVEs (630)

  • CVE-2023-28551HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.

  • CVE-2023-28550HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in MPP performance while accessing DSM watermark using external memory address.

  • CVE-2023-33059HigNov 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Audio while processing the VOC packet data from ADSP.

  • CVE-2023-28541HigJul 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.

  • CVE-2022-33264HigJun 6, 2023
    risk 0.51cvss 7.9epss 0.00

    Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.

  • CVE-2022-25705HigMar 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response

  • CVE-2022-33248HigFeb 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.

  • CVE-2022-33233HigFeb 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption due to configuration weakness in modem wile sending command to write protected files.

  • CVE-2021-35072HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to improper validation of array index while processing external DIAG command in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30333HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30323HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30289HigJan 3, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to lack of range check while processing a DIAG command for COEX management in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30268HigJan 3, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-30255HigNov 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to improper input validation in PDM DIAG command in FTM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-30254HigNov 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2021-1973HigNov 12, 2021
    risk 0.51cvss 7.8epss 0.00

    A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1959HigOct 20, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible memory corruption due to lack of bound check of input index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2020-11292HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.01

    Possible buffer overflow in voice service due to lack of input validation of parameters in QMI Voice API in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2020-11240HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Memory corruption due to ioctl command size was incorrectly set to the size of a pointer and not enough storage is allocated for the copy of the user argument in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2020-11239HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Use after free issue when importing a DMA buffer by using the CPU address of the buffer due to attachment is not cleaned up properly in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

Page 17 of 32