| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to obtain sensitive information from kernel stack memory via (1) a crafted MSM_MCR_IOCTL_EVT_GET ioctl call, related to drivers/media/platform/msm/camera_v1/mercury/msm_mercury_sync.c, or (2) a crafted MSM_JPEG_IOCTL_EVT_GET ioctl call, related to drivers/media/platform/msm/camera_v2/jpeg_10/msm_jpeg_sync.c. |
| Untrusted search path vulnerability in Qualcomm eXtensible Diagnostic Monitor (QXDM) 03.09.19 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc71enu.dll that is located in the same folder as a .isf file. |
| Denial of service in MODEM due to improper pointer handling |
| Information exposure in DSP services due to improper handling of freeing memory |
| Memory corruption in video driver due to type confusion error during video playback |
| Memory corruption due to stack-based buffer overflow in Core |
| Memory corruption due to buffer copy without checking size of input in modem while receiving WMI_REQUEST_STATS_CMDID command. |
| Memory corruption in android core due to improper validation of array index while returning feature ids after license authentication. |
| Memory corruption in Audio due to integer overflow to buffer overflow while music playback of clips like amr,evrc,qcelp with modified content. |
| Transient DOS due to buffer over-read in WLAN while parsing corrupted NAN frames. |
| Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame. |
| Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer. |
| Memory corruption in Automotive due to improper input validation. |
| Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping. |
| Memory corruption in display due to double free while allocating frame buffer memory |
| Memory corruption in Multimedia Framework due to unsafe access to the data members |
| Memory corruption in display driver due to incorrect type casting while accessing the fence structure fields |
| Memory corruption in Bluetooth HOST due to buffer overflow while parsing the command response received from remote |
| Denial of service while processing fastboot flash command on mmc due to buffer over read |
| Information disclosure due to buffer overread in Core |