| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Memory corruption in video while parsing invalid mp2 clip. |
| Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size. |
| Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. |
| Information disclosure while parsing dts header atom in Video. |
| Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
| Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. |
| Transient DOS while parse fils IE with length equal to 1. |
| Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| Transient DOS while processing received beacon frame. |
| Memory corruption while processing manipulated payload in video firmware. |
| Memory Corruption in WLAN HOST while parsing QMI response message from firmware. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |
| Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory. |
| Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. |
| Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. |
| Memory corruption in HLOS while running playready use-case. |
| The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption. |