VYPR

Qcs6125 Firmware

by Qualcomm

CVEs (261)

  • CVE-2021-1895MedMay 7, 2021
    risk 0.44cvss 6.8epss 0.00

    Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

  • CVE-2020-11231MedApr 7, 2021
    risk 0.44cvss 6.7epss 0.00

    Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruption in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2020-11308MedMar 17, 2021
    risk 0.44cvss 6.8epss 0.00

    Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2025-21465MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while processing the hash segment in an MBN file.

  • CVE-2025-21464MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while reading data from an image using specified offset and size parameters.

  • CVE-2021-35070MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    RPM secure Stream can access any secure resource due to improper SMMU configuration and can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-1960MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

  • CVE-2021-1957MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Improper Access Control when ACL link encryption is failed and ACL link is not disconnected during reconnection with paired device in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2025-21433MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.

  • CVE-2024-45551MedApr 7, 2025
    risk 0.40cvss 6.2epss 0.00

    Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.

  • CVE-2023-28563MedNov 7, 2023
    risk 0.40cvss 6.1epss 0.00

    Information disclosure in IOE Firmware while handling WMI command.

  • CVE-2021-1969MedOct 20, 2021
    risk 0.40cvss 6.2epss 0.00

    Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice…

  • CVE-2021-1968MedOct 20, 2021
    risk 0.40cvss 6.2epss 0.00

    Improper validation of kernel buffer address while copying information back to user buffer can lead to kernel memory information exposure to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice…

  • CVE-2021-1929MedSep 8, 2021
    risk 0.40cvss 6.2epss 0.00

    Lack of strict validation of bootmode can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-1904MedSep 8, 2021
    risk 0.40cvss 6.2epss 0.01

    Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2023-28586MedDec 5, 2023
    risk 0.39cvss 6.0epss 0.00

    Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.

  • CVE-2020-11294MedMay 7, 2021
    risk 0.38cvss 5.9epss 0.00

    Out of bound write in logger due to prefix size is not validated while prepended to logging string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2024-33043MedSep 2, 2024
    risk 0.36cvss 5.5epss 0.00

    Transient DOS while handling PS event when Program Service name length offset value is set to 255.

  • CVE-2020-11221MedMar 17, 2021
    risk 0.36cvss 5.5epss 0.00

    Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon…

  • CVE-2020-11199MedMar 17, 2021
    risk 0.36cvss 5.5epss 0.00

    HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…

Page 13 of 14