VYPR

Msm8996au Firmware

by Qualcomm

CVEs (664)

  • CVE-2021-1984HigOct 20, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible buffer overflow due to improper validation of index value while processing the plugin block in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

  • CVE-2021-1983HigOct 20, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible buffer overflow due to improper handling of negative data length while processing write request in VR service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

  • CVE-2021-1949HigOct 20, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible integer overflow due to improper check of batch count value while sanitizer is enabled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30261HigSep 17, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-30260HigSep 17, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuration command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…

  • CVE-2021-1890HigJul 13, 2021
    risk 0.55cvss 8.4epss 0.00

    Improper length check of public exponent in RSA import key function could cause memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1888HigJul 13, 2021
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1886HigJul 13, 2021
    risk 0.55cvss 8.4epss 0.00

    Incorrect handling of pointers in trusted application key import mechanism could cause memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-1900HigJun 9, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible use after free in Display due to race condition while creating an external display in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2020-11234HigApr 7, 2021
    risk 0.55cvss 8.4epss 0.00

    When sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread resulting in a Use After Free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…

  • CVE-2018-5891HigJul 6, 2018
    risk 0.55cvss 8.4epss 0.00

    While processing modem SSR after IMS is registered, the IMS data daemon is restarted but the ipc_dataHandle is no longer available. Consequently, the DPL thread frees the internal memory for dataDHandle but the local variable pointer is not updated which can lead to a Use After…

  • CVE-2025-21488HigSep 24, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set.

  • CVE-2025-21487HigSep 24, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.

  • CVE-2025-21484HigSep 24, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.

  • CVE-2025-21427HigJul 8, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.

  • CVE-2024-53026HigJun 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.

  • CVE-2024-53020HigJun 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure may occur while decoding the RTP packet with invalid header extension from network.

  • CVE-2024-45552HigApr 7, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.

  • CVE-2023-43555HigJun 3, 2024
    risk 0.53cvss 8.2epss 0.00

    Information disclosure in Video while parsing mp2 clip with invalid section length.

  • CVE-2023-24849HigOct 3, 2023
    risk 0.53cvss 8.2epss 0.00

    Information Disclosure in data Modem while parsing an FMTP line in an SDP message.

Page 12 of 34