| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Information disclosure while handling T2LM Action Frame in WLAN Host. |
| Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Transient DOS while parse fils IE with length equal to 1. |
| Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP. |
| Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. |
| Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Memory corruption while processing MBSSID beacon containing several subelement IE. |
| Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
| Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. |
| Memory corruption in HLOS while checking for the storage type. |
| Memory corruption while verifying the serialized header when the key pairs are generated. |
| Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
| Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. |
| Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
| Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. |
| Memory corruption when processing cmd parameters while parsing vdev. |
| Transient DOS when processing a NULL buffer while parsing WLAN vdev. |
| Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. |