VYPR

Qcs4290 Firmware

by Qualcomm

CVEs (481)

  • CVE-2023-22386HigJul 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory.

  • CVE-2023-21670HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.

  • CVE-2023-21657HigJun 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Memoru corruption in Audio when ADSP sends input during record use case.

  • CVE-2022-33264HigJun 6, 2023
    risk 0.51cvss 7.9epss 0.00

    Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.

  • CVE-2022-33278HigMar 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.

  • CVE-2022-33242HigMar 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.

  • CVE-2022-25705HigMar 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response

  • CVE-2022-33248HigFeb 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.

  • CVE-2022-33233HigFeb 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption due to configuration weakness in modem wile sending command to write protected files.

  • CVE-2022-22070HigSep 2, 2022
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-35094HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper verification of timeout-based authentication in identity credential can lead to invalid authorization in HLOS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35072HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to improper validation of array index while processing external DIAG command in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-35106HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30333HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1950HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-35069HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2021-30323HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30319HigJan 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible integer overflow due to improper validation of command length parameters while processing WMI command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2021-30303HigJan 3, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2021-30289HigJan 3, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to lack of range check while processing a DIAG command for COEX management in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Page 13 of 25