| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory Corruption in Data Modem while making a MO call or MT VOLTE call. |
| Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur. |
| Memory corruption while processing finish_sign command to pass a rsp buffer. |
| Memory corruption while invoking IOCTLs calls in Automotive Multimedia. |
| Transient DOS in Bluetooth Host while rfc slot allocation. |
| Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise. |
| Memory Corruption in WLAN HOST while parsing QMI response message from firmware. |
| Memory corruption when two threads try to map and unmap a single node simultaneously. |
| Memory corruption while processing data packets in diag received from Unix clients. |
| Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory. |
| Memory Corruption in Audio while allocating the ion buffer during the music playback. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |
| Transient DOS may occur while processing the country IE. |
| Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem. |
| Information Disclosure in data Modem while parsing an FMTP line in an SDP message. |
| Memory corruption in display driver while detaching a device. |
| Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. |
| Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer. |