| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. |
| Memory corruption while calling the NPU driver APIs concurrently. |
| Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network. |
| While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| Memory corruption may occur while validating ports and channels in Audio driver. |
| Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |
| Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. |
| Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory. |
| Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. |
| Transient DOS while handling PS event when Program Service name length offset value is set to 255. |
| Memory corruption while processing API calls to NPU with invalid input. |
| Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. |
| Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. |
| Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. |
| Memory corruption while performing finish HMAC operation when context is freed by keymaster. |
| Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE. |
| Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE. |
| The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it. |