VYPR

Qca4004 Firmware

by Qualcomm

CVEs (163)

  • CVE-2025-27054HigOct 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing a malformed license file during reboot.

  • CVE-2025-27053HigOct 9, 2025
    risk 0.51cvss 7.8epss 0.00

    Memory corruption during PlayReady APP usecase while processing TA commands.

  • CVE-2024-21465HigJul 1, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing key blob passed by the user.

  • CVE-2023-43542HigJun 3, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.

  • CVE-2023-33018HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while using the UIM diag command to get the operators name.

  • CVE-2023-33017HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.

  • CVE-2023-28551HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.

  • CVE-2023-28550HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in MPP performance while accessing DSM watermark using external memory address.

  • CVE-2023-28546HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in SPS Application while exporting public key in sorter TA.

  • CVE-2023-28565HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while handling command streams through WMI interfaces.

  • CVE-2023-28560HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.

  • CVE-2022-25705HigMar 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response

  • CVE-2022-33233HigFeb 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption due to configuration weakness in modem wile sending command to write protected files.

  • CVE-2021-30323HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30289HigJan 3, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to lack of range check while processing a DIAG command for COEX management in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30268HigJan 3, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-30259HigNov 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible out of bound access due to improper validation of function table entries in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon…

  • CVE-2021-30255HigNov 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to improper input validation in PDM DIAG command in FTM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-30254HigNov 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to improper input validation in factory calibration and test DIAG command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2021-1973HigNov 12, 2021
    risk 0.51cvss 7.8epss 0.00

    A FTM Diag command can allow an arbitrary write into modem OS space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Page 5 of 9