| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. |
| Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. |
| Memory Corruption in Data Modem while processing DMA buffer release event about CFR data. |
| Transient DOS while parse fils IE with length equal to 1. |
| Memory Corruption in Audio while allocating the ion buffer during the music playback. |
| Memory corruption while playing audio file having large-sized input buffer. |
| Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP. |
| Transient DOS in Bluetooth Host while rfc slot allocation. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level. |
| Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise. |
| Cryptographic issue occurs due to use of insecure connection method while downloading. |
| Memory corruption in Audio when memory map command is executed consecutively in ADSP. |
| Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. |
| Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL. |
| Memory corruption while loading an ELF segment in TEE Kernel. |
| Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. |
| Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command. |
| Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. |