CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Memory corruption during management frame processing due to mismatch in T2LM info element. | 9.8 |
Critical |
||
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface. | 7.8 |
High |
||
Memory corruption while parsing the ML IE due to invalid frame content. | 9.8 |
Critical |
||
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | 7.5 |
High |
||
Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | 8.4 |
High |
||
Transient DOS while parsing fragments of MBSSID IE from beacon frame. | 7.5 |
High |
||
Transient DOS while parsing probe response and assoc response frame. | 7.5 |
High |
||
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. | 8.2 |
High |
||
Memory corruption while redirecting log file to any file location with any file name. | 9.8 |
Critical |
||
Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame. | 7.5 |
High |
||
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. | 7.5 |
High |
||
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. | 7.5 |
High |
||
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. | 7.5 |
High |
||
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp. | 7.5 |
High |
||
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. | 7.5 |
High |
||
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length. | 7.5 |
High |
||
Transient DOS while parsing the received TID-to-link mapping action frame. | 7.5 |
High |
||
Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame. | 7.5 |
High |
||
Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less than neighbor report. | 7.5 |
High |
||
Transient DOS while parsing ESP IE from beacon/probe response frame. | 7.5 |
High |
||
Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length. | 7.5 |
High |
||
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. | 7.5 |
High |
||
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. | 7.5 |
High |
||
Transient DOS while parsing fragments of MBSSID IE from beacon frame. | 7.5 |
High |
||
Information disclosure while handling beacon probe frame during scan entry generation in client side. | 7.5 |
High |
||
Information disclosure while handling beacon or probe response frame in STA. | 7.5 |
High |
||
Memory corruption when allocating and accessing an entry in an SMEM partition. | 7.8 |
High |
||
Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image. | 7.8 |
High |
||
Information disclosure while parsing sub-IE length during new IE generation. | 7.5 |
High |
||
Transient DOS while loading the TA ELF file. | 7.1 |
High |
||
Information disclosure while handling SA query action frame. | 7.5 |
High |
||
INformation disclosure while handling Multi-link IE in beacon frame. | 7.5 |
High |
||
Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame. | 7.5 |
High |
||
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame. | 7.5 |
High |
||
Memory corruption while redirecting log file to any file location with any file name. | 9.8 |
Critical |
||
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE. | 9.8 |
Critical |
||
Memory corruption while processing MBSSID beacon containing several subelement IE. | 9.8 |
Critical |
||
Memory corruption while processing TPC target power table in FTM TPC. | 8.4 |
High |
||
Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame. | 7.5 |
High |
||
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number. | 7.5 |
High |
||
Memory corruption in Core Services while executing the command for removing a single event listener. | 9.3 |
Critical |
||
Transient DOS while parse fils IE with length equal to 1. | 7.5 |
High |
||
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. | 7.5 |
High |
||
Transient DOS while processing 11AZ RTT management action frame received through OTA. | 7.5 |
High |
||
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. | 7.5 |
High |
||
Memory corruption in Core while processing control functions. | 9.3 |
Critical |