CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | 8.4 |
Haute |
||
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE. | 7.5 |
Haute |
||
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | 7.5 |
Haute |
||
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA. | 7.5 |
Haute |
||
Memory corruption when an invoke call and a TEE call are bound for the same trusted application. | 7.8 |
Haute |
||
Memory corruption while processing key blob passed by the user. | 7.8 |
Haute |
||
Transient DOS while loading the TA ELF file. | 7.1 |
Haute |
||
Memory corruption in Core Services while executing the command for removing a single event listener. | 9.3 |
Critique |
||
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled. | 7.8 |
Haute |
||
Memory corruption in Core while processing control functions. | 9.3 |
Critique |
||
Transient DOS in Core when DDR memory check is called while DDR is not initialized. | 7.1 |
Haute |
||
Information disclosure in Modem while processing SIB5. | 9.1 |
Critique |
||
Transient DOS in Multi-Mode Call Processor while processing UE policy container. | 7.5 |
Haute |
||
Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage. | 7.5 |
Haute |
||
Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation. | 7.8 |
Haute |
||
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption. | 7.8 |
Haute |
||
Transient DOS in Data Modem during DTLS handshake. | 7.5 |
Haute |
||
Memory corruption while receiving a message in Bus Socket Transport Server. | 7.8 |
Haute |
||
Memory corruption in Audio during playback with speaker protection. | 8.4 |
Haute |
||
Memory corruption in HLOS while running playready use-case. | 9.3 |
Critique |
||
Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call. | 9.8 |
Critique |
||
Information disclosure in Core services while processing a Diag command. | 7.6 |
Haute |
||
Transient DOS in Data modem while handling TLB control messages from the Network. | 7.5 |
Haute |
||
Transient DOS in Modem when a Beam switch request is made with a non-configured BWP. | 7.5 |
Haute |
||
Transient DOS in Modem after RRC Setup message is received. | 7.5 |
Haute |
||
Memory corruption while using the UIM diag command to get the operators name. | 7.8 |
Haute |
||
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | 6.5 |
Moyen |
||
Memory corruption while loading an ELF segment in TEE Kernel. | 8.8 |
Haute |
||
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. | 7.8 |
Haute |
||
Memory corruption in MPP performance while accessing DSM watermark using external memory address. | 7.8 |
Haute |
||
Memory corruption in core services when Diag handler receives a command to configure event listeners. | 9 |
Critique |
||
Memory corruption in TZ Secure OS while loading an app ELF. | 8.2 |
Haute |
||
Memory Corruption in Core due to secure memory access by user while loading modem image. | 8.4 |
Haute |
||
Memory Corruption in Multi-mode Call Processor while processing bit mask API. | 9.8 |
Critique |
||
Cryptographic issue in Data Modem due to improper authentication during TLS handshake. | 9.1 |
Critique |
||
Memory corruption in Modem while processing security related configuration before AS Security Exchange. | 9.8 |
Critique |
||
Information Disclosure in data Modem while parsing an FMTP line in an SDP message. | 8.2 |
Haute |
||
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. | 8.2 |
Haute |
||
Transient DOS in Modem while allocating DSM items. | 7.5 |
Haute |
||
Memory Corruption in Core while invoking a call to Access Control core library with hardware protected address range. | 8.4 |
Haute |
||
Memory Corruption in Data Modem while making a MO call or MT VOLTE call. | 9.8 |
Critique |
||
Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network. | 7.5 |
Haute |
||
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. | 7.5 |
Haute |
||
Information disclosure in Kernel due to indirect branch misprediction. | 7.1 |
Haute |
||
Transient DOS due to improper authorization in Modem | 7.5 |
Haute |
||
Memory corruption due to double free in Core while mapping HLOS address to the list. | 8.4 |
Haute |
||
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. | 7.9 |
Haute |
||
Transient DOS due to reachable assertion in Modem because of invalid network configuration. | 7.5 |
Haute |
||
information disclosure due to cryptographic issue in Core during RPMB read request. | 7.1 |
Haute |
||
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. | 7.5 |
Haute |
||
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported. | 7.5 |
Haute |
||
Transient DOS due to reachable assertion in Modem during OSI decode scheduling. | 7.5 |
Haute |
||
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH. | 7.5 |
Haute |
||
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | 7.8 |
Haute |
||
Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message. | 7.8 |
Haute |
||
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | 6.8 |
Moyen |
||
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. | 9.3 |
Critique |
||
Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message. | 7.5 |
Haute |
||
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment. | 9.3 |
Critique |
||
Memory corruption due to double free in core while initializing the encryption key. | 9.3 |
Critique |