CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
Memory corruption while processing API calls to NPU with invalid input. | 7.8 |
Haute |
||
Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | 8.4 |
Haute |
||
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. | 6.2 |
Moyen |
||
Memory corruption while performing finish HMAC operation when context is freed by keymaster. | 8.4 |
Haute |
||
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | 7.5 |
Haute |
||
Memory corruption in Audio during playback with speaker protection. | 8.4 |
Haute |
||
Memory corruption in HLOS while running playready use-case. | 9.3 |
Critique |
||
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | 6.5 |
Moyen |
||
Memory Corruption in SPS Application while exporting public key in sorter TA. | 7.8 |
Haute |
||
Information disclosure in IOE Firmware while handling WMI command. | 6.1 |
Moyen |
||
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application. | 7.8 |
Haute |
||
Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload. | 7.8 |
Haute |
||
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. | 8.4 |
Haute |
||
Memory corruption due to double free in Core while mapping HLOS address to the list. | 8.4 |
Haute |
||
information disclosure due to cryptographic issue in Core during RPMB read request. | 7.1 |
Haute |
||
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. | 8.4 |
Haute |
||
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | 8.4 |
Haute |
||
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length. | 8.2 |
Haute |
||
Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet. | 8.2 |
Haute |
||
Memory corruption due to double free in core while initializing the encryption key. | 9.3 |
Critique |