CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | 8.4 |
Haute |
||
Memory corruption while processing GPU page table switch. | 7.8 |
Haute |
||
Memory corruption while processing voice packet with arbitrary data received from ADSP. | 7.8 |
Haute |
||
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | 7.5 |
Haute |
||
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. | 9.1 |
Critique |
||
Memory corruption when there is failed unmap operation in GPU. | 8.4 |
Haute |
||
Memory corruption in Audio while processing RT proxy port register driver. | 8.4 |
Haute |
||
Memory corruption in Audio while processing the calibration data returned from ACDB loader. | 7.8 |
Haute |
||
Memory corruption in Audio while processing IIR config data from AFE calibration block. | 7.8 |
Haute |
||
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. | 7.8 |
Haute |
||
Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. | 7.5 |
Haute |
||
Memory corruption in Audio when memory map command is executed consecutively in ADSP. | 7.8 |
Haute |
||
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption. | 7.8 |
Haute |
||
Memory corruption in Audio during playback with speaker protection. | 8.4 |
Haute |
||
Memory corruption in HLOS while running playready use-case. | 9.3 |
Critique |
||
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. | 7.5 |
Haute |
||
Memory corruption while using the UIM diag command to get the operators name. | 7.8 |
Haute |
||
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. | 7.8 |
Haute |
||
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. | 7.8 |
Haute |
||
Memory corruption in MPP performance while accessing DSM watermark using external memory address. | 7.8 |
Haute |
||
Memory corruption in Audio while processing the VOC packet data from ADSP. | 7.8 |
Haute |
||
Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer. | 7.8 |
Haute |
||
Memory Corruption in Multi-mode Call Processor while processing bit mask API. | 9.8 |
Critique |
||
Information Disclosure in data Modem while parsing an FMTP line in an SDP message. | 8.2 |
Haute |
||
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. | 8.2 |
Haute |
||
Memory Corruption in Data Modem while making a MO call or MT VOLTE call. | 9.8 |
Critique |
||
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command. | 8.4 |
Haute |
||
Transient DOS due to improper authorization in Modem | 7.5 |
Haute |
||
Memory corruption due to double free in Core while mapping HLOS address to the list. | 8.4 |
Haute |
||
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. | 7.9 |
Haute |
||
information disclosure due to cryptographic issue in Core during RPMB read request. | 7.1 |
Haute |
||
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. | 8.4 |
Haute |
||
Memory corruption in Graphics while importing a file. | 8.4 |
Haute |
||
Information disclosure due to buffer over-read in Modem while parsing DNS hostname. | 8.2 |
Haute |
||
Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet. | 7.5 |
Haute |
||
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | 8.4 |
Haute |
||
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. | 8.2 |
Haute |
||
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | 7.8 |
Haute |
||
Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. | 7.8 |
Haute |
||
Information disclosure in Modem due to buffer over-read while parsing the wms message received given the buffer and its length. | 8.2 |
Haute |
||
Transient DOS in Modem due to NULL pointer dereference while receiving response of lwm2m registration/update/bootstrap request message. | 7.5 |
Haute |
||
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length. | 8.2 |
Haute |
||
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | 6.8 |
Moyen |
||
Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet. | 8.2 |
Haute |
||
Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received. | 9.8 |
Critique |
||
Information disclosure due to buffer over-read in modem while reading configuration parameters. | 8.2 |
Haute |
||
Information disclosure sue to buffer over-read in modem while processing ipv6 packet with hop-by-hop or destination option in header. | 8.2 |
Haute |
||
Transient DOS in Modem due to null pointer dereference while processing the incoming packet with http chunked encoding. | 7.5 |
Haute |
||
Information disclosure due to buffer over-read while parsing DNS response packets in Modem. | 8.2 |
Haute |
||
memory corruption in modem due to improper check while calculating size of serialized CoAP message | 9.8 |
Critique |
||
Information disclosure in modem due to improper input validation during parsing of upcoming CoAP message | 8.2 |
Haute |
||
Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface | 9.8 |
Critique |
||
Denial of service in modem due to missing null check while processing the ipv6 packet received during ECM call | 7.5 |
Haute |
||
Information disclosure in modem due to missing NULL check while reading packets received from local network | 7.5 |
Haute |
||
Information disclosure in modem due to buffer over-read while processing packets from DNS server | 7.5 |
Haute |
||
Information disclosure in modem due to improper check of IP type while processing DNS server query | 8.2 |
Haute |
||
Information disclosure in modem data due to array out of bound access while handling the incoming DNS response packet | 8.2 |
Haute |
||
Memory correction in modem due to buffer overwrite during coap connection | 9.8 |
Critique |