CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase. |
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame. |
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon. |
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. |
Transient DOS due to improper input validation in WLAN Host. |
Transient DOS due to improper input validation in WLAN Host while parsing frame during defragmentation. |
Transient DOS due to buffer over-read in WLAN Host while parsing frame information. |
Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs. |
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command. |
Information disclosure due to buffer over-read in WLAN while parsing NMF frame. |
Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host |
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. |
An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music |
Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables |
Possible out of bound write due to improper validation of number of timer values received from firmware while syncing timers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking |
Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking |
Possible buffer over read due to lack of size validation while copying data from DBR buffer to RX buffer and can lead to Denial of Service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking |
Improper validation of data length received from DMA buffer can lead to memory corruption. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking |
Transient DOS while parsing ESP IE from beacon/probe response frame. |
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report. |