CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
Memory corruption during management frame processing due to mismatch in T2LM info element. | 9.8 |
Critique |
||
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface. | 7.8 |
Haute |
||
Memory corruption while parsing the ML IE due to invalid frame content. | 9.8 |
Critique |
||
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. | 7.5 |
Haute |
||
Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which this element is present. | 7.5 |
Haute |
||
Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | 8.4 |
Haute |
||
Transient DOS while parsing probe response and assoc response frame. | 7.5 |
Haute |
||
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. | 8.2 |
Haute |
||
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. | 7.5 |
Haute |
||
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. | 7.5 |
Haute |
||
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. | 7.5 |
Haute |
||
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp. | 7.5 |
Haute |
||
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. | 7.5 |
Haute |
||
Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE length. | 7.5 |
Haute |
||
Transient DOS while parsing ESP IE from beacon/probe response frame. | 7.5 |
Haute |
||
Information disclosure while handling beacon probe frame during scan entry generation in client side. | 7.5 |
Haute |
||
Information disclosure while handling beacon or probe response frame in STA. | 7.5 |
Haute |
||
Memory corruption when allocating and accessing an entry in an SMEM partition. | 7.8 |
Haute |
||
Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image. | 7.8 |
Haute |
||
Information disclosure while parsing sub-IE length during new IE generation. | 7.5 |
Haute |
||
Transient DOS while loading the TA ELF file. | 7.1 |
Haute |
||
Information disclosure while handling SA query action frame. | 7.5 |
Haute |
||
INformation disclosure while handling Multi-link IE in beacon frame. | 7.5 |
Haute |
||
Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame. | 7.5 |
Haute |
||
Information disclosure while handling T2LM Action Frame in WLAN Host. | 7.5 |
Haute |
||
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame. | 7.5 |
Haute |
||
Memory corruption while redirecting log file to any file location with any file name. | 9.8 |
Critique |
||
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE. | 9.8 |
Critique |
||
Memory corruption while processing MBSSID beacon containing several subelement IE. | 9.8 |
Critique |
||
Memory corruption while processing TPC target power table in FTM TPC. | 8.4 |
Haute |
||
Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame. | 7.5 |
Haute |
||
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number. | 7.5 |
Haute |
||
Memory corruption in Core Services while executing the command for removing a single event listener. | 9.3 |
Critique |
||
Transient DOS while parse fils IE with length equal to 1. | 7.5 |
Haute |
||
Transient DOS while processing 11AZ RTT management action frame received through OTA. | 7.5 |
Haute |
||
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL. | 7.5 |
Haute |
||
Memory corruption in Core while processing control functions. | 9.3 |
Critique |
||
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | 7.5 |
Haute |
||
Transient DOS while parsing ieee80211_parse_mscs_ie in WIN WLAN driver. | 7.5 |
Haute |
||
Transient DOS while processing a WMI P2P listen start command (0xD00A) sent from host. | 7.5 |
Haute |
||
Transient DOS in WLAN Firmware while parsing a BTM request. | 7.5 |
Haute |
||
Transient DOS while parsing WPA IES, when it is passed with length more than expected size. | 7.5 |
Haute |
||
Transient DOS in WLAN Firmware while processing a FTMR frame. | 7.5 |
Haute |
||
Transient DOS when processing a NULL buffer while parsing WLAN vdev. | 7.5 |
Haute |
||
Memory corruption when processing cmd parameters while parsing vdev. | 8.4 |
Haute |
||
Memory corruption in WLAN Host while processing RRM beacon on the AP. | 9.8 |
Critique |
||
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE. | 9.8 |
Critique |
||
Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast. | 7.5 |
Haute |
||
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. | 7.5 |
Haute |
||
Memory corruption in Kernel while parsing metadata. | 8.4 |
Haute |
||
Under certain scenarios the WLAN Firmware will reach an assertion due to state confusion while looking up peer ids. | 7.5 |
Haute |
||
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | 6.5 |
Moyen |
||
Memory corruption while loading an ELF segment in TEE Kernel. | 8.8 |
Haute |
||
Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame. | 7.5 |
Haute |
||
Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE. | 7.5 |
Haute |
||
Transient DOS in WLAN Firmware while parsing t2lm buffers. | 7.5 |
Haute |
||
Transient DOS in WLAN Firmware while parsing no-inherit IES. | 7.5 |
Haute |
||
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute. | 9.8 |
Critique |
||
Memory Corruption in Core due to secure memory access by user while loading modem image. | 8.4 |
Haute |
||
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache. | 9.8 |
Critique |
||
Transient DOS in WLAN Firmware while parsing rsn ies. | 7.5 |
Haute |
||
Transient DOS in WLAN Firmware while parsing a NAN management frame. | 7.5 |
Haute |