| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. |
| Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. |
| Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers. |
| Information disclosure in Audio while accessing AVCS services from ADSP payload. |
| Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. |
| Memory corruption when two threads try to map and unmap a single node simultaneously. |
| Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
| Memory corruption in HLOS while converting from authorization token to HIDL vector. |
| Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers. |
| Memory corruption during concurrent access to server info object due to unprotected critical field. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| Memory corruption in HLOS while checking for the storage type. |
| Memory corruption while verifying the serialized header when the key pairs are generated. |
| Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |
| Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Memory corruption when IOMMU unmap of a GPU buffer fails in Linux. |
| Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory. |