CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking |
information disclosure due to cryptographic issue in Core during RPMB read request. |
Memory corruption in BT controller due to improper length check while processing vendor specific commands in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking |
Possible out of bound write due to improper validation of number of timer values received from firmware while syncing timers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking |
Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking |
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking |
Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking |
Transient DOS while parsing ESP IE from beacon/probe response frame. |
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report. |
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. |
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length. |
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame. |
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp. |
Transient DOS while parsing the received TID-to-link mapping action frame. |
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions. |
Memory corruption while redirecting log file to any file location with any file name. |