VYPR

Qcn7606 Firmware

by Qualcomm

CVEs (166)

  • CVE-2021-30303HigJan 3, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2020-11235HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2021-1915HigMay 7, 2021
    risk 0.51cvss 7.8epss 0.00

    Buffer overflow can occur due to improper validation of NDP application information length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2019-10527HigSep 8, 2020
    risk 0.51cvss 7.8epss 0.00

    u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SMEM address range which could lead to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics…

  • CVE-2019-14037HigJul 30, 2020
    risk 0.51cvss 7.8epss 0.00

    Close and bind operations done on a socket can lead to a Use-After-Free condition. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…

  • CVE-2023-21652HigAug 8, 2023
    risk 0.50cvss 7.7epss 0.00

    Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.

  • CVE-2025-47318HigSep 24, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing the EPTM test control message to get the test pattern.

  • CVE-2025-27066HigAug 6, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing an ANQP message.

  • CVE-2024-33051HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

  • CVE-2023-43536HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parse fils IE with length equal to 1.

  • CVE-2023-43512HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing GATT service data when the total amount of memory that is required by the multiple services is greater than the actual size of the services buffer.

  • CVE-2023-43511HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header.

  • CVE-2023-33109HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host.

  • CVE-2023-33062HigJan 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing a BTM request.

  • CVE-2023-33098HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing WPA IES, when it is passed with length more than expected size.

  • CVE-2023-33080HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.

  • CVE-2023-28588HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Bluetooth Host while rfc slot allocation.

  • CVE-2023-33027HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing rsn ies.

  • CVE-2023-24847HigOct 3, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Modem while allocating DSM items.

  • CVE-2023-33015HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.

Page 5 of 9