| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory Corruption in WLAN HOST while parsing QMI WLAN Firmware response message. |
| Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| Memory corruption in MPP performance while accessing DSM watermark using external memory address. |
| Memory Corruption in Audio while allocating the ion buffer during the music playback. |
| Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
| Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command. |
| Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. |
| Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Memory corruption while using the UIM diag command to get the operators name. |
| Memory corruption in Audio while processing RT proxy port register driver. |
| Information Disclosure in data Modem while parsing an FMTP line in an SDP message. |
| Transient DOS while parse fils IE with length equal to 1. |
| Memory corruption in Audio when memory map command is executed consecutively in ADSP. |
| Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Memory corruption when there is failed unmap operation in GPU. |
| Memory corruption when two threads try to map and unmap a single node simultaneously. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |