| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Memory corruption while processing pin reply in Bluetooth, when pin code received from APP layer is greater than expected size. |
| Memory corruption when multiple listeners are being registered with the same file descriptor. |
| Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers. |
| Information disclosure in WLAN HAL while handling command through WMI interfaces. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. |
| Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application. |
| Memory Corruption in WLAN HOST while parsing QMI response message from firmware. |
| Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command. |
| Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command. |
| Memory Corruption in Audio while allocating the ion buffer during the music playback. |
| Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element. |
| Transient DOS in Modem while allocating DSM items. |
| Transient DOS in Audio when invoking callback function of ASM driver. |
| Memory corruption while using the UIM diag command to get the operators name. |
| Memory corruption while processing multiple simultaneous escape calls. |
| Memory corruption while processing manipulated payload in video firmware. |