| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Transient DOS while processing DL NAS TRANSPORT message with payload length 0. |
| Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. |
| Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
| Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP. |
| Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE. |
| Memory corruption when multiple listeners are being registered with the same file descriptor. |
| Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
| Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. |
| Information disclosure while handling T2LM Action Frame in WLAN Host. |
| Memory corruption while invoking HGSL IOCTL context create. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. |
| Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers. |
| Memory corruption while retrieving the CBOR data from TA. |
| Memory Corruption in SPS Application while exporting public key in sorter TA. |
| Memory corruption in MPP performance while accessing DSM watermark using external memory address. |