VYPR

Qca9377 Firmware

by Qualcomm

CVEs (560)

  • CVE-2025-27064MedNov 4, 2025
    risk 0.40cvss 6.1epss 0.00

    Information disclosure while registering commands from clients with diag through diagHal.

  • CVE-2025-27030MedSep 24, 2025
    risk 0.40cvss 6.1epss 0.00

    information disclosure while invoking calibration data from user space to update firmware size.

  • CVE-2024-38417MedFeb 3, 2025
    risk 0.40cvss 6.1epss 0.00

    Information disclosure while processing IO control commands.

  • CVE-2024-38416MedFeb 3, 2025
    risk 0.40cvss 6.1epss 0.00

    Information disclosure during audio playback.

  • CVE-2024-33067MedJan 6, 2025
    risk 0.40cvss 6.1epss 0.00

    Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.

  • CVE-2023-43528MedMay 6, 2024
    risk 0.40cvss 6.1epss 0.00

    Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.

  • CVE-2023-28563MedNov 7, 2023
    risk 0.40cvss 6.1epss 0.00

    Information disclosure in IOE Firmware while handling WMI command.

  • CVE-2022-22075MedMar 10, 2023
    risk 0.40cvss 6.2epss 0.00

    Information Disclosure in Graphics during GPU context switch.

  • CVE-2021-35135MedSep 2, 2022
    risk 0.40cvss 6.2epss 0.00

    A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-1904MedSep 8, 2021
    risk 0.40cvss 6.2epss 0.01

    Child process can leak information from parent process due to numeric pids are getting compared and these pid can be reused in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2023-28586MedDec 5, 2023
    risk 0.39cvss 6.0epss 0.00

    Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE.

  • CVE-2020-3664MedFeb 22, 2021
    risk 0.39cvss 6.0epss 0.00

    Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon…

  • CVE-2023-43530MedMay 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Memory corruption in HLOS while checking for the storage type.

  • CVE-2023-33076MedFeb 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

  • CVE-2022-33266MedJan 9, 2023
    risk 0.38cvss 5.9epss 0.00

    Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content.

  • CVE-2025-47369MedJan 7, 2026
    risk 0.36cvss 5.5epss 0.00

    Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.

  • CVE-2025-47330MedJan 7, 2026
    risk 0.36cvss 5.5epss 0.00

    Transient DOS while parsing video packets received from the video firmware.

  • CVE-2025-27041MedOct 9, 2025
    risk 0.36cvss 5.5epss 0.00

    Transient DOS while processing video packets received from video firmware.

  • CVE-2025-21472MedAug 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Information disclosure while capturing logs as eSE debug messages are logged.

  • CVE-2024-43046MedApr 7, 2025
    risk 0.36cvss 5.5epss 0.00

    There may be information disclosure during memory re-allocation in TZ Secure OS.

Page 27 of 28