VYPR

Sm4350 Firmware

by Qualcomm

CVEs (39)

  • CVE-2020-11182CriJun 9, 2021
    risk 0.64cvss 9.8epss 0.01

    Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2020-11261HigKEVJun 9, 2021
    risk 0.63cvss 7.8epss 0.02

    Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2023-33054CriDec 5, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.

  • CVE-2023-28540CriOct 3, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in Data Modem due to improper authentication during TLS handshake.

  • CVE-2020-11276CriFeb 22, 2021
    risk 0.59cvss 9.1epss 0.01

    Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation of P2P IE and NOA attribute lengths in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…

  • CVE-2020-11275CriFeb 22, 2021
    risk 0.59cvss 9.1epss 0.01

    Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial…

  • CVE-2023-33022HigDec 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in HLOS while invoking IOCTL calls from user-space.

  • CVE-2020-11260HigJun 9, 2021
    risk 0.55cvss 8.4epss 0.00

    An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2023-33018HigDec 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while using the UIM diag command to get the operators name.

  • CVE-2023-33031HigNov 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.

  • CVE-2023-33035HigOct 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while invoking callback function of AFE from ADSP.

  • CVE-2023-28560HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.

  • CVE-2023-21656HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HOST while receiving an WMI event from firmware.

  • CVE-2020-11178HigJun 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with its memory and its RoT memory in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2020-11204HigFeb 22, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for parameters that are read from shared MSG RAM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…

  • CVE-2020-11195HigFeb 22, 2021
    risk 0.51cvss 7.8epss 0.00

    Out of bound write and read in TA while processing command from NS side due to improper length check on command and response buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2020-11194HigFeb 22, 2021
    risk 0.51cvss 7.8epss 0.00

    Possible out of bound access in TA while processing a command from NS side due to improper length check of response buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired…

  • CVE-2023-33043HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Modem when a Beam switch request is made with a non-configured BWP.

  • CVE-2023-33042HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Transient DOS in Modem after RRC Setup message is received.

  • CVE-2023-28555HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Audio while remapping channel buffer in media codec decoding.

Page 1 of 2