VYPR

Qca1990 Firmware

by Qualcomm

CVEs (26)

  • CVE-2021-1920CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.01

    Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1916CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.01

    Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music,…

  • CVE-2020-11170CriFeb 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…

  • CVE-2022-25718CriOct 19, 2022
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…

  • CVE-2021-1924CriNov 12, 2021
    risk 0.59cvss 9.0epss 0.00

    Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…

  • CVE-2020-11159CriJun 9, 2021
    risk 0.59cvss 9.1epss 0.01

    Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length of frame pointer being accessed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon…

  • CVE-2020-11276CriFeb 22, 2021
    risk 0.59cvss 9.1epss 0.01

    Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation of P2P IE and NOA attribute lengths in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…

  • CVE-2020-11269HigFeb 22, 2021
    risk 0.57cvss 8.8epss 0.00

    Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2020-11303HigOct 20, 2021
    risk 0.56cvss 8.6epss 0.01

    Accepting AMSDU frames with mismatched destination and source address can lead to information disclosure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…

  • CVE-2023-21628HigJun 6, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.

  • CVE-2022-40532HigApr 13, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.

  • CVE-2022-25655HigMar 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.

  • CVE-2021-30261HigSep 17, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible integer and heap overflow due to lack of input command size validation while handling beacon template update command from HLOS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2021-30260HigSep 17, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuration command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…

  • CVE-2022-25719HigOct 19, 2022
    risk 0.53cvss 8.2epss 0.00

    Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile,…

  • CVE-2020-11191HigApr 7, 2021
    risk 0.53cvss 8.2epss 0.01

    Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon…

  • CVE-2023-28565HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while handling command streams through WMI interfaces.

  • CVE-2023-28560HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.

  • CVE-2021-1959HigOct 20, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible memory corruption due to lack of bound check of input index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2020-11292HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.01

    Possible buffer overflow in voice service due to lack of input validation of parameters in QMI Voice API in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…

Page 1 of 2