| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames. |
| Information disclosure due to buffer over-read in WLAN while parsing BTM action frame. |
| Information disclosure due to buffer over-read in WLAN while WLAN frame parsing due to missing frame length check. |
| Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP. |
| Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound model list is empty in HLOS drive. |
| Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend. |
| Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image. |
| Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU. |
| Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range. |
| Memory corruption in Core Platform while printing the response buffer in log. |
| Memory Corruption in Core Platform while printing the response buffer in log. |
| Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART. |
| Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload. |
| Memory corruption in WLAN HAL while passing command parameters through WMI interfaces. |
| Memory corruption in WLAN HAL while handling command through WMI interfaces. |
| Weak configuration in Automotive while VM is processing a listener request from TEE. |
| Memory Corruption in HLOS while registering for key provisioning notify. |
| Memory corruption in Automotive Display while destroying the image handle created using connected display driver. |
| Memory corruption in Automotive Multimedia due to integer overflow to buffer overflow during IOCTL calls in video playback. |
| Information disclosure while parsing the OCI IE with invalid length. |