| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Information Disclosure in data Modem while parsing an FMTP line in an SDP message. |
| Memory corruption while processing command in Glink linux. |
| Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware. |
| Memory corruption when user provides data for FM HCI command control operations. |
| Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time. |
| Memory corruption in Modem while processing security related configuration before AS Security Exchange. |
| Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level. |
| Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL. |
| Memory corruption while parsing qcp clip with invalid chunk data size. |
| Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. |
| Memory corruption in UTILS when modem processes memory specific Diag commands having arbitrary address values as input arguments. |
| Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage. |
| Information disclosure in WLAN HAL while handling the WMI state info command. |
| Memory corruption during management frame processing due to mismatch in T2LM info element. |
| While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| Transient DOS during hypervisor virtual I/O operation in a virtual machine. |
| Transient DOS in Bluetooth Host while rfc slot allocation. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |