VYPR

Sm8150 Firmware

by Qualcomm

CVEs (316)

  • CVE-2019-10574HigApr 16, 2020
    risk 0.46cvss 7.1epss 0.02

    Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…

  • CVE-2019-14081HigMar 5, 2020
    risk 0.46cvss 7.1epss 0.00

    Buffer Over-read when WLAN module gets a WMI message for SAR limits with invalid number of limits to be enforced in Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired…

  • CVE-2019-14072HigMar 5, 2020
    risk 0.46cvss 7.0epss 0.00

    Unhandled paging request is observed due to dereferencing an already freed object because of race condition between sparse free and sparse bind ioctls which access the same physical entry in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2019-2338HigDec 12, 2019
    risk 0.46cvss 7.1epss 0.00

    Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to the secure world in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2019-10486HigNov 21, 2019
    risk 0.46cvss 7.0epss 0.00

    Race condition due to the lack of resource lock which will be concurrently modified in the memcpy statement leads to out of bound access in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…

  • CVE-2023-33024MedDec 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption while sending SMS from AP firmware.

  • CVE-2022-33267MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Linux while sending DRM request.

  • CVE-2022-33263MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to use after free in Core when multiple DCI clients register and deregister.

  • CVE-2022-33230MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host

  • CVE-2022-33227MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in Linux android due to double free while calling unregister provider after register call.

  • CVE-2022-33226MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from diag client applications.

  • CVE-2022-33224MedJun 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries.

  • CVE-2022-33302MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.

  • CVE-2022-33298MedApr 13, 2023
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to use after free in Modem while modem initialization.

  • CVE-2022-33289MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.

  • CVE-2022-33296MedApr 13, 2023
    risk 0.38cvss 5.9epss 0.00

    Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.

  • CVE-2019-10482MedDec 18, 2019
    risk 0.38cvss 5.9epss 0.01

    Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a potential side channel for SUI corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2020-11123MedNov 12, 2020
    risk 0.36cvss 5.5epss 0.00

    u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at getting user`s lock-screen password can be bypassed by performing the standard gatekeeper operations.' in Snapdragon Auto, Snapdragon Compute,…

  • CVE-2020-3679MedSep 9, 2020
    risk 0.36cvss 5.5epss 0.00

    u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known address including code segments' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2020-3644MedSep 8, 2020
    risk 0.36cvss 5.5epss 0.00

    u'Information disclosure issue occurs as in current logic Secure Touch session is released without terminating display session' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

Page 15 of 16