VYPR

Qcs4290 Firmware

by Qualcomm

CVEs (481)

  • CVE-2026-24077MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.

  • CVE-2025-59610MedJun 1, 2026
    risk 0.42cvss 6.4epss 0.00

    Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.

  • CVE-2025-47404MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.

  • CVE-2025-47371MedMar 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when an LTE RLC packet with invalid TB is received by UE.

  • CVE-2025-21465MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while processing the hash segment in an MBN file.

  • CVE-2025-21464MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while reading data from an image using specified offset and size parameters.

  • CVE-2021-35080MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    Disabled SMMU from secure side while RPM is assigned a secure stream can lead to information disclosure in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-30346MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-30345MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-30348MedJan 3, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

  • CVE-2020-11220MedMar 17, 2021
    risk 0.42cvss 6.4epss 0.00

    While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT,…

  • CVE-2025-21433MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.

  • CVE-2024-45551MedApr 7, 2025
    risk 0.40cvss 6.2epss 0.00

    Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.

  • CVE-2024-23357MedAug 5, 2024
    risk 0.40cvss 6.2epss 0.00

    Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.

  • CVE-2022-40533MedJun 6, 2023
    risk 0.40cvss 6.2epss 0.00

    Transient DOS due to untrusted Pointer Dereference in core while sending USB QMI request.

  • CVE-2022-22075MedMar 10, 2023
    risk 0.40cvss 6.2epss 0.00

    Information Disclosure in Graphics during GPU context switch.

  • CVE-2022-25679MedNov 15, 2022
    risk 0.40cvss 6.2epss 0.00

    Denial of service in video due to improper access control in broadcast receivers in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2021-35135MedSep 2, 2022
    risk 0.40cvss 6.2epss 0.00

    A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-35079MedJun 14, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30314MedJan 13, 2022
    risk 0.40cvss 6.2epss 0.00

    Lack of validation for third party application accessing the service can lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables