| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Transient DOS when processing a NULL buffer while parsing WLAN vdev. |
| Transient DOS while parsing WPA IES, when it is passed with length more than expected size. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. |
| Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
| Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
| Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Transient DOS while processing 11AZ RTT management action frame received through OTA. |
| Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver. |
| Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present. |
| Memory corruption when allocating and accessing an entry in an SMEM partition continuously. |
| Memory corruption in WLAN Host while processing RRM beacon on the AP. |
| Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. |
| Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length. |
| Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. |
| Transient DOS while parsing fragments of MBSSID IE from beacon frame. |
| Information disclosure while handling beacon probe frame during scan entry generation in client side. |
| Memory corruption when allocating and accessing an entry in an SMEM partition. |
| Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image. |