| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Improper Access to the VM resource manager can lead to Memory Corruption. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command. |
| Information disclosure while deriving keys for a session for any Widevine use case. |
| Memory corruption in Audio when memory map command is executed consecutively in ADSP. |
| Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. |
| Transient DOS may occur while processing the country IE. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data. |
| Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| Information disclosure in Audio while accessing AVCS services from ADSP payload. |
| While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
| Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
| Memory corruption while using the UIM diag command to get the operators name. |
| Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. |
| Transient DOS while parsing WPA IES, when it is passed with length more than expected size. |
| Memory corruption in Audio while processing IIR config data from AFE calibration block. |
| Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL. |