| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| Memory corruption while playing audio file having large-sized input buffer. |
| Transient DOS in Audio when invoking callback function of ASM driver. |
| Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location. |
| Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame. |
| Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
| Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
| Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. |
| Memory corruption in Core Services while executing the command for removing a single event listener. |
| Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command. |
| Memory corruption in Core while processing control functions. |
| Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. |
| Memory corruption when BTFM client sends new messages over Slimbus to ADSP. |
| Memory corruption while processing finish_sign command to pass a rsp buffer. |
| Memory corruption while copying the result to the transmission queue which is shared between the virtual machine and the host. |
| Memory corruption in Core when updating rollback version for TA and OTA feature is enabled. |
| Memory corruption in Automotive Multimedia due to improper access control in HAB. |
| Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend. |
| Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image. |
| Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU. |