VYPR

Snapdragon 425 Mobile Platform Firmware

by Qualcomm

CVEs (38)

  • CVE-2023-33110HigJan 2, 2024
    risk 0.51cvss 7.8epss 0.00

    The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.

  • CVE-2023-33018HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while using the UIM diag command to get the operators name.

  • CVE-2023-28551HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments.

  • CVE-2023-28550HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in MPP performance while accessing DSM watermark using external memory address.

  • CVE-2023-28546HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in SPS Application while exporting public key in sorter TA.

  • CVE-2023-33059HigNov 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Audio while processing the VOC packet data from ADSP.

  • CVE-2023-24850HigOct 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.

  • CVE-2022-33264HigJun 6, 2023
    risk 0.51cvss 7.9epss 0.00

    Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.

  • CVE-2025-21428HigApr 7, 2025
    risk 0.49cvss 7.5epss 0.00

    Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.

  • CVE-2024-23385HigNov 4, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.

  • CVE-2024-23358HigSep 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

  • CVE-2024-23353HigAug 5, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.

  • CVE-2023-28588HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Bluetooth Host while rfc slot allocation.

  • CVE-2022-40521HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS due to improper authorization in Modem

  • CVE-2025-21482HigSep 24, 2025
    risk 0.46cvss 7.1epss 0.00

    Cryptographic issue while performing RSA PKCS padding decoding.

  • CVE-2022-22076HigJun 6, 2023
    risk 0.46cvss 7.1epss 0.00

    information disclosure due to cryptographic issue in Core during RPMB read request.

  • CVE-2024-23357MedAug 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.

  • CVE-2024-33043MedSep 2, 2024
    risk 0.36cvss 5.5epss 0.00

    Transient DOS while handling PS event when Program Service name length offset value is set to 255.

Page 2 of 2