| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory corruption while processing finish_sign command to pass a rsp buffer. |
| Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP. |
| Memory corruption while processing audio effects. |
| Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. |
| Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Transient DOS in WLAN Firmware while parsing a NAN management frame. |
| Memory corruption when multiple listeners are being registered with the same file descriptor. |
| Memory corruption in WLAN Firmware while doing a memory copy of pmk cache. |
| Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message. |
| Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. |
| Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation. |
| Memory corruption while processing MBSSID beacon containing several subelement IE. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |
| Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem. |
| Memory corruption while invoking IOCTLs calls in Automotive Multimedia. |
| Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers. |