| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. |
| Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
| Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
| Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
| Memory corruption in DSP Services during a remote call from HLOS to DSP. |
| memory corruption when an invalid firehose patch command is invoked. |
| Memory corruption while processing video packets received from video firmware. |
| Memory Corruption in Audio while allocating the ion buffer during the music playback. |
| Information disclosure in WLAN HAL while handling the WMI state info command. |
| Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. |
| Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. |
| Memory corruption when there is failed unmap operation in GPU. |
| Information disclosure in WLAN HAL while handling command through WMI interfaces. |
| Memory Corruption in WLAN HOST while fetching TX status information. |
| While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers. |
| Transient DOS in Bluetooth Host while rfc slot allocation. |
| Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. |
| Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |