VYPR

Qcs2290 Firmware

by Qualcomm

CVEs (451)

  • CVE-2022-40519MedJan 9, 2023
    risk 0.44cvss 6.8epss 0.00

    Information disclosure due to buffer overread in Core

  • CVE-2022-40518MedJan 9, 2023
    risk 0.44cvss 6.8epss 0.00

    Information disclosure due to buffer overread in Core

  • CVE-2022-25676MedNov 15, 2022
    risk 0.44cvss 6.8epss 0.00

    Information disclosure in video due to buffer over-read while parsing avi files in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-35121MedJun 14, 2022
    risk 0.44cvss 6.7epss 0.00

    An array index is improperly used to lock and unlock a mutex which can lead to a Use After Free condition In the Synx driver in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35120MedJun 14, 2022
    risk 0.44cvss 6.7epss 0.00

    Improper handling between export and release functions on the same handle from client can lead to use after free in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35118MedJun 14, 2022
    risk 0.44cvss 6.7epss 0.00

    An out-of-bounds write can occur due to an incorrect input check in the camera driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30313MedJan 13, 2022
    risk 0.44cvss 6.7epss 0.00

    Use after free condition can occur in wired connectivity due to a race condition while creating and deleting folders in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2021-1931MedJul 13, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible buffer overflow due to improper validation of buffer length while processing fast boot commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2021-1895MedMay 7, 2021
    risk 0.44cvss 6.8epss 0.00

    Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

  • CVE-2020-11308MedMar 17, 2021
    risk 0.44cvss 6.8epss 0.00

    Buffer overflow occurs when trying to convert ASCII string to Unicode string if the actual size is more than required in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2020-11198MedFeb 22, 2021
    risk 0.44cvss 6.7epss 0.00

    Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage of memset in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2025-47333MedJan 7, 2026
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while handling buffer mapping operations in the cryptographic driver.

  • CVE-2026-24078MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

  • CVE-2026-24077MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.

  • CVE-2025-59610MedJun 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.

  • CVE-2025-47404MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.

  • CVE-2025-47371MedMar 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when an LTE RLC packet with invalid TB is received by UE.

  • CVE-2025-21465MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while processing the hash segment in an MBN file.

  • CVE-2025-21464MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while reading data from an image using specified offset and size parameters.

  • CVE-2021-35080MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    Disabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables