| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| Transient DOS in Bluetooth Host while rfc slot allocation. |
| Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. |
| Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
| Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. |
| Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element. |
| Transient DOS while parsing probe response and assoc response frame. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |
| Memory corruption when resource manager sends the host kernel a reply message with multiple fragments. |
| Transient DOS while parse fils IE with length equal to 1. |
| Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
| Information disclosure in WLAN HOST while processing the WLAN scan descriptor list during roaming scan. |
| Cryptographic issue in HLOS during key management. |
| Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers. |
| Transient DOS while parsing WPA IES, when it is passed with length more than expected size. |
| Memory Corruption in Audio while allocating the ion buffer during the music playback. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Memory corruption when Alternative Frequency offset value is set to 255. |