VYPR

Qca9888 Firmware

by Qualcomm

CVEs (296)

  • CVE-2021-30266MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible use after free due to improper memory validation when initializing new interface via Interface add command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2021-30264MedNov 12, 2021
    risk 0.44cvss 6.7epss 0.00

    Possible use after free due improper validation of reference from call back to internal store table in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon…

  • CVE-2021-1962MedSep 9, 2021
    risk 0.44cvss 6.7epss 0.00

    Buffer Overflow while processing IOCTL for getting peripheral endpoint information there is no proper validation for input maximum endpoint pair and its size in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables,…

  • CVE-2021-1895MedMay 7, 2021
    risk 0.44cvss 6.8epss 0.00

    Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

  • CVE-2020-11198MedFeb 22, 2021
    risk 0.44cvss 6.7epss 0.00

    Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage of memset in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile,…

  • CVE-2023-28539MedOct 3, 2023
    risk 0.43cvss 6.6epss 0.00

    Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.

  • CVE-2025-47403MedMay 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.

  • CVE-2025-47325MedDec 18, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while processing system calls with invalid parameters.

  • CVE-2025-27040MedOct 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure may occur while processing the hypervisor log.

  • CVE-2025-21465MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while processing the hash segment in an MBN file.

  • CVE-2025-21464MedAug 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while reading data from an image using specified offset and size parameters.

  • CVE-2024-21467MedAug 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while handling beacon probe frame during scan entry generation in client side.

  • CVE-2024-21459MedAug 5, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while handling beacon or probe response frame in STA.

  • CVE-2024-21458MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while handling SA query action frame.

  • CVE-2024-21457MedJul 1, 2024
    risk 0.42cvss 6.5epss 0.00

    INformation disclosure while handling Multi-link IE in beacon frame.

  • CVE-2023-43537MedJun 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Information disclosure while handling T2LM Action Frame in WLAN Host.

  • CVE-2021-30346MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-30345MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.00

    RPM secure Stream can access any secure resource due to improper SMMU configuration in Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

  • CVE-2020-11266MedJun 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Image address is dereferenced before validating its range which can cause potential QSEE information leakage in Snapdragon Wired Infrastructure and Networking

  • CVE-2020-11220MedMar 17, 2021
    risk 0.42cvss 6.4epss 0.00

    While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT,…

Page 14 of 15