CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
Information disclosure due to buffer over-read in Bluetooth HOST while pairing and connecting A2DP. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
Transient DOS due to loop with unreachable exit condition in WLAN while processing an incoming FTM frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking |
Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content. |
Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data. |
Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed. |
Transient DOS due to buffer over-read in WLAN while processing 802.11 management frames. |
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames. |
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM |
Memory corruption in WLAN HAL while handling command streams through WMI interfaces. |
Information disclosure while parsing the OCI IE with invalid length. |
Information disclosure during audio playback. |
Information disclosure while processing IO control commands. |
Memory corruption when the bandpass filter order received from AHAL is not within the expected range. |
Memory corruption due to double free in Core while mapping HLOS address to the list. |
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. |
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length. |
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. |
Transient DOS while parsing fragments of MBSSID IE from beacon frame. |