VYPR

Sm8450 Firmware

by Qualcomm

CVEs (81)

  • CVE-2022-33273HigMay 2, 2023
    risk 0.47cvss 7.3epss 0.00

    Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.

  • CVE-2021-30272HigJan 3, 2022
    risk 0.47cvss 7.3epss 0.00

    Possible null pointer dereference in thread cache operation handler due to lack of validation of user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2021-30271HigJan 3, 2022
    risk 0.47cvss 7.3epss 0.00

    Possible null pointer dereference in trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2021-30269HigJan 3, 2022
    risk 0.47cvss 7.3epss 0.00

    Possible null pointer dereference due to lack of TLB validation for user provided address in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music,…

  • CVE-2022-40529HigJun 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Memory corruption due to improper access control in kernel while processing a mapping request from root process.

  • CVE-2022-40523HigJun 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Information disclosure in Kernel due to indirect branch misprediction.

  • CVE-2022-22076HigJun 6, 2023
    risk 0.46cvss 7.1epss 0.00

    information disclosure due to cryptographic issue in Core during RPMB read request.

  • CVE-2021-1894HigJan 3, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper access control in TrustZone due to improper error handling while handling the signing key in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and…

  • CVE-2022-33263MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to use after free in Core when multiple DCI clients register and deregister.

  • CVE-2022-33226MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications.

  • CVE-2022-33224MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries.

  • CVE-2022-33281MedMay 2, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending any frames.

  • CVE-2022-33302MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.

  • CVE-2022-33289MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.

  • CVE-2021-30266MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2021-30264MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible use after free due improper validation of reference from call back to internal store table in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon…

  • CVE-2021-30348MedJan 3, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2022-40533MedJun 6, 2023
    risk 0.40cvss 6.2epss 0.00

    Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.

  • CVE-2022-33296MedApr 13, 2023
    risk 0.38cvss 5.9epss 0.00

    Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.

  • CVE-2022-33303MedJun 6, 2023
    risk 0.36cvss 5.5epss 0.00

    Transient DOS due to uncontrolled resource consumption in Linux kernel when malformed messages are sent from the Gunyah Resource Manager message queue.

Page 4 of 5