VYPR

Qcn9022 Firmware

by Qualcomm

CVEs (244)

  • CVE-2022-40531HigMar 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in WLAN due to incorrect type cast while sending WMI_SCAN_SCH_PRIO_TBL_CMDID message.

  • CVE-2022-40530HigMar 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.

  • CVE-2022-25655HigMar 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.

  • CVE-2022-33277HigFeb 12, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.

  • CVE-2022-33243HigFeb 12, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption due to improper access control in Qualcomm IPC.

  • CVE-2022-40517HigJan 9, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in core due to stack-based buffer overflow

  • CVE-2022-40516HigJan 9, 2023
    risk 0.55cvss 8.4epss 0.01

    Memory corruption in Core due to stack-based buffer overflow.

  • CVE-2022-33276HigJan 9, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption due to buffer copy without checking size of input in modem while receiving WMI_REQUEST_STATS_CMDID command.

  • CVE-2021-30281HigJun 14, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice &…

  • CVE-2021-30337HigJan 3, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible use after free when process shell memory is freed using IOCTL call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2021-30335HigJan 3, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible assertion in QOS request due to improper validation when multiple add or update request are received simultaneously in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2021-30282HigJan 3, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible out of bound write in RAM partition table due to improper validation on number of partitions provided in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2021-30274HigJan 3, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible integer overflow in access control initialization interface due to lack and size and address validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2021-30288HigOct 20, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible stack overflow due to improper length check of TLV while copying the TLV to a local stack variable in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT,…

  • CVE-2021-30260HigSep 17, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan hostlist configuration command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity,…

  • CVE-2020-11267HigJun 9, 2021
    risk 0.55cvss 8.4epss 0.00

    Stack out-of-bounds write occurs while setting up a cipher device if the provided IV length exceeds the max limit value in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2021-1927HigMay 7, 2021
    risk 0.55cvss 8.4epss 0.00

    Possible use after free due to lack of null check while memory is being freed in FastRPC driver in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables,…

  • CVE-2026-24088HigJun 1, 2026
    risk 0.53cvss 8.2epss 0.00

    Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.

  • CVE-2024-49839HigFeb 3, 2025
    risk 0.53cvss 8.2epss 0.00

    Memory corruption during management frame processing due to mismatch in T2LM info element.

  • CVE-2024-38408HigNov 4, 2024
    risk 0.53cvss 8.2epss 0.00

    Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

Page 3 of 13