VYPR

Qcs410 Firmware

by Qualcomm

CVEs (324)

  • CVE-2025-21465MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while processing the hash segment in an MBN file.

  • CVE-2025-21464MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while reading data from an image using specified offset and size parameters.

  • CVE-2023-28576MedAug 8, 2023
    risk 0.42cvss 6.4epss 0.00

    The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid.…

  • CVE-2021-30348MedJan 3, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2021-1960MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

  • CVE-2025-27030MedSep 24, 2025
    risk 0.40cvss 6.1epss 0.00

    information disclosure while invoking calibration data from user space to update firmware size.

  • CVE-2024-33067MedJan 6, 2025
    risk 0.40cvss 6.1epss 0.00

    Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.

  • CVE-2023-28563MedNov 7, 2023
    risk 0.40cvss 6.1epss 0.00

    Information disclosure in IOE Firmware while handling WMI command.

  • CVE-2023-28554MedNov 7, 2023
    risk 0.40cvss 6.1epss 0.00

    Information Disclosure in Qualcomm IPC while reading values from shared memory in VM.

  • CVE-2021-1969MedOct 20, 2021
    risk 0.40cvss 6.2epss 0.00

    Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice…

  • CVE-2021-1968MedOct 20, 2021
    risk 0.40cvss 6.2epss 0.00

    Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice…

  • CVE-2021-1904MedSep 8, 2021
    risk 0.40cvss 6.2epss 0.01

    Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2023-28586MedDec 5, 2023
    risk 0.39cvss 6.0epss 0.00

    Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.

  • CVE-2020-3664MedFeb 22, 2021
    risk 0.39cvss 6.0epss 0.00

    Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2022-33266MedJan 9, 2023
    risk 0.38cvss 5.9epss 0.00

    Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content.

  • CVE-2025-27041MedOct 9, 2025
    risk 0.36cvss 5.5epss 0.00

    Transient DOS while processing video packets received from video firmware.

  • CVE-2024-33043MedSep 2, 2024
    risk 0.36cvss 5.5epss 0.00

    Transient DOS while handling PS event when Program Service name length offset value is set to 255.

  • CVE-2023-33111MedApr 1, 2024
    risk 0.36cvss 5.5epss 0.00

    Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command.

  • CVE-2023-33064MedFeb 6, 2024
    risk 0.36cvss 5.5epss 0.00

    Transient DOS in Audio when invoking callback function of ASM driver.

  • CVE-2020-11221MedMar 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon…

Page 16 of 17