VYPR

Qcm4290 Firmware

by Qualcomm

CVEs (289)

  • CVE-2021-1927HigMay 7, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables,…

  • CVE-2021-1891HigMay 7, 2021
    risk 0.55cvss 8.4epss 0.00

    A possible use-after-free occurrence in audio driver can happen when pointers are not properly handled in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2020-11284HigMay 7, 2021
    risk 0.55cvss 8.4epss 0.00

    Locked memory can be unlocked and modified by non secure boot loader through improper system call sequence making the memory region untrusted source of input for secure boot loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2020-11246HigApr 7, 2021
    risk 0.55cvss 8.4epss 0.00

    A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2020-11245HigApr 7, 2021
    risk 0.55cvss 8.4epss 0.00

    Unintended reads and writes by NS EL2 in access control driver due to lack of check of input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and…

  • CVE-2025-21487HigSep 24, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.

  • CVE-2024-53026HigJun 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.

  • CVE-2024-53021HigJun 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure may occur while processing goodbye RTCP packet from network.

  • CVE-2024-53020HigJun 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Information disclosure may occur while decoding the RTP packet with invalid header extension from network.

  • CVE-2023-28585HigDec 5, 2023
    risk 0.53cvss 8.2epss 0.00

    Memory corruption while loading an ELF segment in TEE Kernel.

  • CVE-2023-24849HigOct 3, 2023
    risk 0.53cvss 8.2epss 0.00

    Information Disclosure in data Modem while parsing an FMTP line in an SDP message.

  • CVE-2023-24848HigOct 3, 2023
    risk 0.53cvss 8.2epss 0.00

    Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.

  • CVE-2023-22385HigOct 3, 2023
    risk 0.53cvss 8.2epss 0.00

    Memory Corruption in Data Modem while making a MO call or MT VOLTE call.

  • CVE-2023-21669HigJun 6, 2023
    risk 0.53cvss 8.2epss 0.00

    Information Disclosure in WLAN HOST while sending DPP action frame to peer with an invalid source address.

  • CVE-2022-33235HigDec 13, 2022
    risk 0.53cvss 8.2epss 0.00

    Information disclosure due to buffer over-read in WLAN firmware while parsing security context info attributes. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2021-30349HigJun 14, 2022
    risk 0.53cvss 8.2epss 0.00

    Improper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables,…

  • CVE-2021-35117HigApr 1, 2022
    risk 0.53cvss 8.2epss 0.01

    An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2021-35088HigApr 1, 2022
    risk 0.53cvss 8.2epss 0.01

    Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon…

  • CVE-2020-11285HigMay 7, 2021
    risk 0.53cvss 8.2epss 0.01

    Buffer over-read while unpacking the RTCP packet we may read extra byte if wrong length is provided in RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon…

  • CVE-2020-11251HigApr 7, 2021
    risk 0.53cvss 8.2epss 0.01

    Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon…

Page 6 of 15