| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. |
| Transient DOS in Bluetooth Host while rfc slot allocation. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |
| Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time. |
| Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. |
| Cryptographic issue occurs due to use of insecure connection method while downloading. |
| Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Memory corruption while using the UIM diag command to get the operators name. |
| Memory corruption in WLAN Host while setting the PMK length in PMK length in internal cache. |
| Memory corruption in DSP Service during a remote call from HLOS to DSP. |
| Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command. |
| Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
| Memory corruption when multiple listeners are being registered with the same file descriptor. |
| Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length. |
| Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. |
| Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element. |
| Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL. |
| Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls, |
| Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request. |