VYPR

Snapdragon 8\+ Gen 1 Firmware

by Qualcomm

CVEs (48)

  • CVE-2023-28542HigJul 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in WLAN HOST while fetching TX status information.

  • CVE-2023-28541HigJul 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in Data Modem while processing DMA buffer release event about CFR data.

  • CVE-2023-24854HigJul 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message.

  • CVE-2023-24851HigJul 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in WLAN HOST while parsing QMI response message from firmware.

  • CVE-2023-22387HigJul 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.

  • CVE-2023-22386HigJul 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.

  • CVE-2024-53027HigMar 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Transient DOS may occur while processing the country IE.

  • CVE-2024-33051HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

  • CVE-2024-33050HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.

  • CVE-2023-33016HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN firmware while parsing MLO (multi-link operation).

  • CVE-2023-33015HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.

  • CVE-2023-28584HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA).

  • CVE-2023-21631HigJul 4, 2023
    risk 0.49cvss 7.5epss 0.00

    Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.

  • CVE-2025-47383HigMar 2, 2026
    risk 0.47cvss 7.2epss 0.00

    Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.

  • CVE-2023-28577MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf to get the kernel va to use, another thread can call CAM_REQ_MGR_RELEASE_BUF to unmap the kernel va which cause UAF of the kernel…

  • CVE-2023-28575MedAug 8, 2023
    risk 0.44cvss 6.7epss 0.00

    The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.

  • CVE-2023-21640MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Linux when the file upload API is called with parameters having large buffer.

  • CVE-2023-21638MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.

  • CVE-2023-21629MedJul 4, 2023
    risk 0.44cvss 6.8epss 0.00

    Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.

  • CVE-2025-47333MedJan 7, 2026
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while handling buffer mapping operations in the cryptographic driver.