| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory corruption in HLOS while converting from authorization token to HIDL vector. |
| Memory corruption in Audio while running invalid audio recording from ADSP. |
| Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame. |
| Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR. |
| Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16. |
| Transient DOS while parsing WPA IES, when it is passed with length more than expected size. |
| Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR. |
| Transient DOS while processing DL NAS TRANSPORT message with payload length 0. |
| Transient DOS while processing PDU Release command with a parameter PDU ID out of range. |
| Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command. |
| Transient DOS when WLAN firmware receives "reassoc response" frame including RIC_DATA element. |
| Memory corruption when resource manager sends the host kernel a reply message with multiple fragments. |
| Memory corruption while running NPU, when NETWORK_UNLOAD and (NETWORK_UNLOAD or NETWORK_EXECUTE_V2) commands are submitted at the same time. |
| Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. |
| Memory corruption when HLOS allocates the response payload buffer to copy the data received from ADSP in response to AVCS_LOAD_MODULE command. |
| Memory corruption while processing Listen Sound Model client payload buffer when there is a request for Listen Sound session get parameter from ST HAL. |
| Memory corruption in Audio when memory map command is executed consecutively in ADSP. |
| Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Memory corruption while processing MBSSID beacon containing several subelement IE. |