CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
While processing the authentication message in UE, improper authentication may lead to information disclosure. | 5.4 |
Moyen |
||
Memory corruption while configuring a Hypervisor based input virtual device. | 8.8 |
Haute |
||
Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | 8.4 |
Haute |
||
Memory corruption while Configuring the SMR/S2CR register in Bypass mode. | 8.4 |
Haute |
||
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE. | 7.5 |
Haute |
||
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | 7.5 |
Haute |
||
Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA. | 7.5 |
Haute |
||
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager. | 8.4 |
Haute |
||
Memory corruption when an invoke call and a TEE call are bound for the same trusted application. | 7.8 |
Haute |
||
Memory corruption while processing key blob passed by the user. | 7.8 |
Haute |
||
Transient DOS while loading the TA ELF file. | 7.1 |
Haute |
||
Memory corruption in Hypervisor when platform information mentioned is not aligned. | 9.3 |
Critique |
||
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. | 9.1 |
Critique |
||
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked. | 7.8 |
Haute |
||
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization. | 9.3 |
Critique |
||
Memory corruption in HLOS while checking for the storage type. | 7.8 |
Haute |
||
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. | 7.5 |
Haute |
||
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache. | 8.4 |
Haute |
||
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. | 7.8 |
Haute |
||
Transient DOS while processing DL NAS TRANSPORT message with payload length 0. | 7.5 |
Haute |
||
Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR. | 7.5 |
Haute |
||
Transient DOS while processing PDU Release command with a parameter PDU ID out of range. | 7.5 |
Haute |
||
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16. | 7.5 |
Haute |
||
Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR. | 7.5 |
Haute |
||
Memory corruption in Core Services while executing the command for removing a single event listener. | 9.3 |
Critique |
||
Memory corruption in Core when updating rollback version for TA and OTA feature is enabled. | 7.8 |
Haute |
||
Memory corruption in Core while processing control functions. | 9.3 |
Critique |
||
Transient DOS in Multi-Mode Call Processor while processing UE policy container. | 7.5 |
Haute |
||
Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage. | 7.5 |
Haute |
||
Transient DOS in Data Modem during DTLS handshake. | 7.5 |
Haute |
||
Memory corruption while receiving a message in Bus Socket Transport Server. | 7.8 |
Haute |
||
Permanent DOS in Hypervisor while untrusted VM without PSCI support makes a PSCI call. | 7.1 |
Haute |
||
Memory corruption in Audio during playback with speaker protection. | 8.4 |
Haute |
||
Memory corruption in HLOS while running playready use-case. | 9.3 |
Critique |
||
Transient DOS in Data modem while handling TLB control messages from the Network. | 7.5 |
Haute |
||
Transient DOS in Modem when a Beam switch request is made with a non-configured BWP. | 7.5 |
Haute |
||
Transient DOS in Modem after RRC Setup message is received. | 7.5 |
Haute |
||
Memory corruption while using the UIM diag command to get the operators name. | 7.8 |
Haute |
||
Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. | 6.5 |
Moyen |
||
Memory corruption while loading an ELF segment in TEE Kernel. | 8.8 |
Haute |
||
Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. | 7.8 |
Haute |
||
Memory corruption in MPP performance while accessing DSM watermark using external memory address. | 7.8 |
Haute |
||
Memory corruption in TZ Secure OS while loading an app ELF. | 8.2 |
Haute |
||
Memory Corruption in Core due to secure memory access by user while loading modem image. | 8.4 |
Haute |
||
Memory Corruption in Multi-mode Call Processor while processing bit mask API. | 9.8 |
Critique |
||
Cryptographic issue in Data Modem due to improper authentication during TLS handshake. | 9.1 |
Critique |
||
Memory corruption in Modem while processing security related configuration before AS Security Exchange. | 9.8 |
Critique |
||
Information Disclosure in data Modem while parsing an FMTP line in an SDP message. | 8.2 |
Haute |
||
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. | 8.2 |
Haute |
||
Transient DOS in Modem while allocating DSM items. | 7.5 |
Haute |
||
Memory Corruption in Data Modem while making a MO call or MT VOLTE call. | 9.8 |
Critique |
||
Improper Access to the VM resource manager can lead to Memory Corruption. | 8.7 |
Haute |
||
Memory Corruption in Core Platform while printing the response buffer in log. | 7.8 |
Haute |
||
Memory corruption in Core Platform while printing the response buffer in log. | 7.8 |
Haute |
||
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE. | 9.3 |
Critique |
||
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. | 9.8 |
Critique |
||
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. | 6.8 |
Moyen |
||
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. | 7.5 |
Haute |
||
Information disclosure in Kernel due to indirect branch misprediction. | 7.1 |
Haute |
||
Transient DOS due to improper authorization in Modem | 7.5 |
Haute |
||
Memory corruption due to double free in Core while mapping HLOS address to the list. | 8.4 |
Haute |
||
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. | 7.9 |
Haute |
||
Transient DOS due to reachable assertion in Modem because of invalid network configuration. | 7.5 |
Haute |
||
information disclosure due to cryptographic issue in Core during RPMB read request. | 7.1 |
Haute |
||
Assertion occurs while processing Reconfiguration message due to improper validation | 7.5 |
Haute |
||
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. | 7.5 |
Haute |
||
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation. | 7.3 |
Haute |
||
Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is not supported. | 7.5 |
Haute |
||
Transient DOS due to reachable assertion in Modem during OSI decode scheduling. | 7.5 |
Haute |
||
Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH. | 7.5 |
Haute |
||
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. | 7.8 |
Haute |
||
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. | 6.8 |
Moyen |
||
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information. | 9.3 |
Critique |
||
Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message. | 7.5 |
Haute |
||
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment. | 9.3 |
Critique |
||
Memory corruption due to double free in core while initializing the encryption key. | 9.3 |
Critique |
||
Transient DOS in modem due to reachable assertion. | 7.5 |
Haute |
||
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone. | 9.3 |
Critique |
||
Memory corruption due to improper validation of array index in Multi-mode call processor. | 9.8 |
Critique |
||
Transient DOS due to reachable assertion in Modem while processing SIB1 Message. | 7.5 |
Haute |
||
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover. | 7.5 |
Haute |
||
Transient DOS due to reachable assertion in modem during MIB reception and SIB timeout | 7.5 |
Haute |
||
Memory corruption in modem due to buffer overflow while processing a PPP packet | 8.8 |
Haute |
||
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response | 7.8 |
Haute |
||
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM | 8.4 |
Haute |
||
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http. | 7.8 |
Haute |
||
Memory corruption due to configuration weakness in modem wile sending command to write protected files. | 7.8 |
Haute |
||
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory. | 9.3 |
Critique |
||
Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping. | 8.1 |
Haute |
||
Denial of service in MODEM due to improper pointer handling | 6.2 |
Moyen |
||
Possible memory corruption in kernel while performing memory access due to hypervisor not correctly invalidated the processor translation caches in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | 8.4 |
Haute |
||
Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 8.4 |
Haute |
||
Denial of service in Modem module due to improper authorization while error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | 7.5 |
Haute |
||
Denial of service in Modem due to reachable assertion while processing the common config procedure in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | 7.5 |
Haute |
||
Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 8.4 |
Haute |
||
Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | 7.8 |
Haute |
||
Memory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | 8.4 |
Haute |
||
Information disclosure due to buffer over read in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile | 7.1 |
Haute |
||
Improper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking | 8.2 |
Haute |
||
Reading PRNG output may lead to improper key generation due to lack of buffer validation in Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking | 9 |
Critique |
||
Possible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking | 8.4 |
Haute |
||
Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking | 7.8 |
Haute |
||
Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking | 9.3 |
Critique |
||
Improper validation of memory region in Hypervisor can lead to incorrect region mapping in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking | 9.3 |
Critique |
||
Possible access control violation while setting current permission for VMIDs due to improper permission masking in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking | 7.8 |
Haute |
||
Improper access control while doing XPU re-configuration dynamically can lead to unauthorized access to a secure resource in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wired Infrastructure and Networking | 9.3 |
Critique |
||
Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking | 9.3 |
Critique |
||
Possible integer overflow in access control initialization interface due to lack and size and address validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking | 8.4 |
Haute |
||
Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking | 9 |
Critique |
||
Possible integer overflow due to improper length check while updating grace period and count record in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking | 8.4 |
Haute |