CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
Memory corruption when allocating and accessing an entry in an SMEM partition. | 7.8 |
High |
||
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. | 7.8 |
High |
||
Memory corruption in Audio when memory map command is executed consecutively in ADSP. | 7.8 |
High |
||
Memory corruption in Audio during playback with speaker protection. | 8.4 |
High |
||
Memory corruption in HLOS while running playready use-case. | 9.3 |
Critical |
||
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. | 8.4 |
High |
||
Transient DOS in Bluetooth Host while rfc slot allocation. | 7.5 |
High |
||
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | 6.5 |
Medium |
||
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. | 7.8 |
High |
||
Memory corruption in MPP performance while accessing DSM watermark using external memory address. | 7.8 |
High |
||
Memory Corruption in Audio while invoking IOCTLs calls from the user-space. | 7.8 |
High |
||
Information Disclosure in Qualcomm IPC while reading values from shared memory in VM. | 6.1 |
Medium |
||
Memory Corruption in Multi-mode Call Processor while processing bit mask API. | 9.8 |
Critical |
||
Information Disclosure in data Modem while parsing an FMTP line in an SDP message. | 8.2 |
High |
||
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. | 8.2 |
High |
||
Memory Corruption in Data Modem while making a MO call or MT VOLTE call. | 9.8 |
Critical |