CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver. | 7.8 |
High |
||
Memory corruption while invoking IOCTL calls from user space to set generic private command inside WLAN driver. | 7.8 |
High |
||
Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | 8.4 |
High |
||
Memory corruption while Configuring the SMR/S2CR register in Bypass mode. | 8.4 |
High |
||
Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice. | 7.8 |
High |
||
Memory corruption while station LL statistic handling. | 7.8 |
High |
||
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. | 6.2 |
Medium |
||
Transient DOS while parse fils IE with length equal to 1. | 7.5 |
High |
||
Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger. | 8.4 |
High |
||
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame. | 7.5 |
High |
||
Memory corruption while reading ACPI config through the user mode app. | 8.4 |
High |
||
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. | 7.5 |
High |
||
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled. | 7.8 |
High |
||
Memory corruption in Core while processing control functions. | 9.3 |
Critical |
||
Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation. | 7.8 |
High |
||
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | 7.5 |
High |
||
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption. | 7.8 |
High |
||
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. | 7.5 |
High |
||
Transient DOS in WLAN Firmware while parsing a BTM request. | 7.5 |
High |
||
Cryptographic issue in Automotive while unwrapping the key secs2d and verifying with RPMB data. | 7.1 |
High |
||
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call. | 7.1 |
High |
||
Memory corruption in HLOS while running playready use-case. | 9.3 |
Critical |
||
Cryptographic issue in HLOS during key management. | 7.8 |
High |
||
Memory corruption in TZ Secure OS while loading an app ELF. | 8.2 |
High |
||
Memory Corruption in Core due to secure memory access by user while loading modem image. | 8.4 |
High |
||
Memory corruption in WLAN handler while processing PhyID in Tx status handler. | 7.8 |
High |
||
Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload. | 7.8 |
High |
||
Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART. | 7.8 |
High |
||
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation. | 7.3 |
High |