| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Transient DOS in Bluetooth Host while rfc slot allocation. |
| Memory corruption in wearables while processing data from AON. |
| Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data. |
| Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| Memory corruption during concurrent access to server info object due to unprotected critical field. |
| Transient DOS during hypervisor virtual I/O operation in a virtual machine. |
| Memory Corruption in camera while installing a fd for a particular DMA buffer. |
| Memory Corruption in WLAN HOST while parsing QMI response message from firmware. |
| Memory corruption while invoking callback function of AFE from ADSP. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |
| Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL. |
| Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time. |
| Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
| Memory corruption while running VK synchronization with KASAN enabled. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| Memory corruption in HLOS while converting from authorization token to HIDL vector. |
| Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. |