| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory corruption while parsing the ADSP response command. |
| Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation. |
| Memory corruption in Audio while processing RT proxy port register driver. |
| Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. |
| Memory corruption when resource manager sends the host kernel a reply message with multiple fragments. |
| Memory corruption in SPS Application while requesting for public key in sorter TA. |
| Memory corruption in WLAN Firmware while doing a memory copy of pmk cache. |
| Memory Corruption in camera while installing a fd for a particular DMA buffer. |
| Memory Corruption in Data Modem while making a MO call or MT VOLTE call. |
| Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory. |
| Memory corruption in Modem while processing security related configuration before AS Security Exchange. |
| Memory Corruption in Core due to secure memory access by user while loading modem image. |
| Memory Corruption in WLAN HOST while parsing QMI response message from firmware. |
| Memory corruption in Core Services while executing the command for removing a single event listener. |
| Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request. |
| Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. |
| Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager. |
| Luxion KeyShot DAE File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion KeyShot. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of dae files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-23704. |
| Buffer Overflow vulnerability in Ffmpeg before github commit 4565747056a11356210ed8edcecb920105e40b60 allows a remote attacker to achieve an out-of-array write, execute arbitrary code, and cause a denial of service (DoS) via the ref_pic_list_struct function in libavcodec/evc_ps.c |
| Parallels Desktop virtio-gpu Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Parallels Desktop. User interaction is required to exploit this vulnerability in that the target in a guest system must visit a malicious page or open a malicious file.
The specific flaw exists within the virtio-gpu virtual device. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the hypervisor.
. Was ZDI-CAN-21260. |