CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Memory corruption while processing API calls to NPU with invalid input. | 7.8 |
High |
||
Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | 8.4 |
High |
||
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. | 6.2 |
Medium |
||
Memory corruption while performing finish HMAC operation when context is freed by keymaster. | 8.4 |
High |
||
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | 7.5 |
High |
||
Memory corruption in Audio during playback with speaker protection. | 8.4 |
High |
||
Memory corruption in HLOS while running playready use-case. | 9.3 |
Critical |
||
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | 6.5 |
Medium |
||
Memory Corruption in SPS Application while exporting public key in sorter TA. | 7.8 |
High |
||
Information disclosure in IOE Firmware while handling WMI command. | 6.1 |
Medium |
||
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application. | 7.8 |
High |
||
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. | 7.8 |
High |
||
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. | 8.4 |
High |
||
Memory corruption due to double free in Core while mapping HLOS address to the list. | 8.4 |
High |
||
information disclosure due to cryptographic issue in Core during RPMB read request. | 7.1 |
High |
||
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. | 8.4 |
High |
||
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | 8.4 |
High |
||
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length. | 8.2 |
High |
||
Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet. | 8.2 |
High |
||
Memory corruption due to double free in core while initializing the encryption key. | 9.3 |
Critical |