VYPR

Sa8540p Firmware

by Qualcomm

CVEs (238)

  • CVE-2024-33067MedJan 6, 2025
    risk 0.40cvss 6.1epss 0.00

    Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.

  • CVE-2024-33037MedDec 2, 2024
    risk 0.40cvss 6.1epss 0.00

    Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.

  • CVE-2024-23357MedAug 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.

  • CVE-2022-40533MedJun 6, 2023
    risk 0.40cvss 6.2epss 0.00

    Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.

  • CVE-2022-22101MedSep 2, 2022
    risk 0.40cvss 6.2epss 0.00

    Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdragon Auto

  • CVE-2021-35135MedSep 2, 2022
    risk 0.40cvss 6.2epss 0.00

    A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2023-28586MedDec 5, 2023
    risk 0.39cvss 6.0epss 0.00

    Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.

  • CVE-2022-33216MedFeb 12, 2023
    risk 0.39cvss 6.0epss 0.00

    Transient Denial-of-service in Automotive due to improper input validation while parsing ELF file.

  • CVE-2023-43530MedMay 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Memory corruption in HLOS while checking for the storage type.

  • CVE-2023-33076MedFeb 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

  • CVE-2025-27072MedAug 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Information disclosure while processing a packet at EAVB BE side with invalid header length.

  • CVE-2025-21472MedAug 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Information disclosure while capturing logs as eSE debug messages are logged.

  • CVE-2025-21431MedApr 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Information disclosure may be there when a guest VM is connected.

  • CVE-2024-43046MedApr 7, 2025
    risk 0.36cvss 5.5epss 0.00

    There may be information disclosure during memory re-allocation in TZ Secure OS.

  • CVE-2024-43056MedMar 3, 2025
    risk 0.36cvss 5.5epss 0.00

    Transient DOS during hypervisor virtual I/O operation in a virtual machine.

  • CVE-2024-43051MedMar 3, 2025
    risk 0.36cvss 5.5epss 0.00

    Information disclosure while deriving keys for a session for any Widevine use case.

  • CVE-2024-45559MedJan 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.

  • CVE-2024-53009MedJul 8, 2025
    risk 0.34cvss 5.3epss 0.00

    Memory corruption while operating the mailbox in Automotive.

Page 12 of 12