| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Cryptographic issue occurs due to use of insecure connection method while downloading. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Memory corruption in video while parsing invalid mp2 clip. |
| Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. |
| Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem. |
| Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. |
| Memory corruption while verifying the serialized header when the key pairs are generated. |
| Memory corruption when user provides data for FM HCI command control operations. |
| Memory corruption while processing IOCTL call for getting group info. |
| Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise. |
| Information disclosure may occur due to improper permission and access controls to Video Analytics engine. |
| Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses. |
| Memory corruption while retrieving the CBOR data from TA. |
| Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. |
| Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. |
| Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. |
| Transient DOS while processing received beacon frame. |
| Memory corruption while reading the FW response from the shared queue. |
| Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer. |