CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Memory corruption while power-up or power-down sequence of the camera sensor. | 7.8 |
High |
||
Memory corruption in Camera due to unusually high number of nodes passed to AXI port. | 7.8 |
High |
||
Memory corruption may occour while generating test pattern due to negative indexing of display ID. | 7.8 |
High |
||
Memory corruption while handling IOCTL call from user-space to set latency level. | 7.8 |
High |
||
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer. | 7.8 |
High |
||
Memory corruption while parsing the memory map info in IOCTL calls. | 7.8 |
High |
||
Information disclosure while processing IO control commands. | 6.1 |
Medium |
||
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in modem. | 7.5 |
High |
||
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU. | 7.5 |
High |
||
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver. | 6.1 |
Medium |
||
Memory corruption when two threads try to map and unmap a single node simultaneously. | 8.4 |
High |
||
Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine. | 7.8 |
High |
||
Memory corruption when user provides data for FM HCI command control operations. | 7.8 |
High |
||
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. | 7.5 |
High |
||
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. | 9.1 |
Critical |
||
Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. | 6.1 |
Medium |
||
Information disclosure while parsing dts header atom in Video. | 6.8 |
Medium |
||
Memory corruption when there is failed unmap operation in GPU. | 8.4 |
High |
||
Memory corruption while processing finish_sign command to pass a rsp buffer. | 8.4 |
High |
||
Memory corruption in SPS Application while requesting for public key in sorter TA. | 8.4 |
High |
||
Memory corruption in Audio while processing RT proxy port register driver. | 8.4 |
High |