VYPR

Qca4004 Firmware

by Qualcomm

CVEs (163)

  • CVE-2022-40532HigApr 13, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.

  • CVE-2022-40531HigMar 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.

  • CVE-2022-25694HigMar 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM

  • CVE-2022-40520HigJan 9, 2023
    risk 0.55cvss 8.4epss 0.01

    Memory corruption due to stack-based buffer overflow in Core

  • CVE-2022-40517HigJan 9, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in core due to stack-based buffer overflow

  • CVE-2022-40516HigJan 9, 2023
    risk 0.55cvss 8.4epss 0.01

    Memory corruption in Core due to stack-based buffer overflow.

  • CVE-2022-25695HigDec 13, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice…

  • CVE-2022-25682HigDec 13, 2022
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2021-30281HigJun 14, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice &…

  • CVE-2021-30282HigJan 3, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible out of bound write in RAM partition table due to improper validation on number of partitions provided in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2021-30274HigJan 3, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible integer overflow in access control initialization interface due to lack and size and address validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2021-30261HigSep 17, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-1890HigJul 13, 2021
    risk 0.55cvss 8.4epss 0.00

    Improper length check of public exponent in RSA import key function could cause memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1889HigJul 13, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible buffer overflow due to lack of length check in Trusted Application in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1888HigJul 13, 2021
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1886HigJul 13, 2021
    risk 0.55cvss 8.4epss 0.00

    Incorrect handling of pointers in trusted application key import mechanism could cause memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon…

  • CVE-2024-23359HigSep 2, 2024
    risk 0.53cvss 8.2epss 0.00

    Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

  • CVE-2023-28585HigDec 5, 2023
    risk 0.53cvss 8.2epss 0.00

    Memory corruption while loading an ELF segment in TEE Kernel.

  • CVE-2023-28545HigNov 7, 2023
    risk 0.53cvss 8.2epss 0.00

    Memory corruption in TZ Secure OS while loading an app ELF.

  • CVE-2023-22385HigOct 3, 2023
    risk 0.53cvss 8.2epss 0.00

    Memory Corruption in Data Modem while making a MO call or MT VOLTE call.

Page 3 of 9