| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size. |
| Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. |
| Memory Corruption in WLAN Host while deserializing the input PMK bytes without checking the input PMK length. |
| Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager. |
| Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. |
| Memory corruption in TZ Secure OS while loading an app ELF. |
| Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE. |
| Memory corruption when user provides data for FM HCI command control operations. |
| Information disclosure in WLAN HAL while handling the WMI state info command. |
| Memory corruption in Audio when memory map command is executed consecutively in ADSP. |
| Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem. |
| Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. |
| Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. |
| Information disclosure in WLAN HAL while handling command through WMI interfaces. |
| Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command. |
| Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Transient DOS while parsing probe response and assoc response frame. |