VYPR

bootloader

by Samsung Mobile

CVEs (11)

  • CVE-2016-3850HigAug 5, 2016
    risk 0.47cvss 7.3epss 0.00

    Integer overflow in app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-08-05 on Nexus 5, 5X, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted header field in a boot image, aka Android internal bug 27917291 and Qualcomm internal bug…

  • CVE-2023-42561HigDec 5, 2023
    risk 0.46cvss 7.1epss 0.00

    Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.

  • CVE-2023-21489HigMay 4, 2023
    risk 0.46cvss 7.1epss 0.00

    Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code.

  • CVE-2024-20865MedMay 7, 2024
    risk 0.43cvss 6.6epss 0.00

    Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.

  • CVE-2024-20880MedJun 4, 2024
    risk 0.42cvss 6.4epss 0.00

    Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to overwrite memory.

  • CVE-2025-20892MedFeb 4, 2025
    risk 0.38cvss 5.9epss 0.00

    Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command. User interaction is required for triggering this vulnerability.

  • CVE-2014-9798MedJul 11, 2016
    risk 0.36cvss 5.5epss 0.01

    platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 devices does not check the relationship between tags addresses and aboot addresses, which allows attackers to cause a denial of service (OS outage) via a crafted application, aka…

  • CVE-2024-49422MedDec 31, 2024
    risk 0.34cvss 5.2epss 0.00

    Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnerability.

  • CVE-2024-20882MedJun 4, 2024
    risk 0.30cvss 4.6epss 0.00

    Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.

  • CVE-2024-20820MedFeb 6, 2024
    risk 0.29cvss 4.4epss 0.00

    Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.

  • CVE-2025-58476MedDec 2, 2025
    risk 0.27cvss 4.2epss 0.00

    Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.