VYPR

Qcn9024 Firmware

by Qualcomm

CVEs (454)

  • CVE-2022-33289MedApr 13, 2023
    risk 0.44cvss 6.8epss 0.00

    Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.

  • CVE-2022-40519MedJan 9, 2023
    risk 0.44cvss 6.8epss 0.00

    Information disclosure due to buffer overread in Core

  • CVE-2022-40518MedJan 9, 2023
    risk 0.44cvss 6.8epss 0.00

    Information disclosure due to buffer overread in Core

  • CVE-2022-25677MedDec 13, 2022
    risk 0.44cvss 6.7epss 0.00

    Memory corruption in diag due to use after free while processing dci packet in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

  • CVE-2022-25666MedOct 19, 2022
    risk 0.44cvss 6.7epss 0.00

    Memory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-30325MedFeb 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Possible out of bound access of DCI resources due to lack of validation process and resource allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired…

  • CVE-2021-30324MedFeb 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to remote process in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2021-30313MedJan 13, 2022
    risk 0.44cvss 6.7epss 0.00

    Use after free condition can occur in wired connectivity due to a race condition while creating and deleting folders in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2021-30266MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2021-30264MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible use after free due improper validation of reference from call back to internal store table in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon…

  • CVE-2021-1895MedMay 7, 2021
    risk 0.44cvss 6.8epss 0.00

    Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

  • CVE-2020-11198MedFeb 22, 2021
    risk 0.44cvss 6.7epss 0.00

    Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage of memset in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2025-47333MedJan 7, 2026
    risk 0.43cvss 6.6epss 0.00

    Memory corruption while handling buffer mapping operations in the cryptographic driver.

  • CVE-2023-28539MedOct 3, 2023
    risk 0.43cvss 6.6epss 0.00

    Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.

  • CVE-2026-24078MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

  • CVE-2025-47403MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.

  • CVE-2025-47401MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when processing target power rate tables during channel configuration.

  • CVE-2025-47371MedMar 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when an LTE RLC packet with invalid TB is received by UE.

  • CVE-2025-47325MedDec 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while processing system calls with invalid parameters.

  • CVE-2025-27040MedOct 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure may occur while processing the hypervisor log.