| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. |
| Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message. |
| Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
| Memory corruption when multiple listeners are being registered with the same file descriptor. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Information disclosure while parsing dts header atom in Video. |
| Memory corruption while processing IOCTL handler in FastRPC. |
| Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver. |
| Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. |
| Memory corruption while processing event close when client process terminates abruptly. |
| Memory corruption while processing multiple simultaneous escape calls. |
| Memory corruption while processing a private escape command in an event trigger. |
| Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. |
| Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
| Memory corruption while operating the mailbox in Automotive. |
| Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |