| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Memory corruption in HLOS while converting from authorization token to HIDL vector. |
| Memory corruption while processing data packets in diag received from Unix clients. |
| Memory corruption when the payload received from firmware is not as per the expected protocol size. |
| Memory corruption while processing buffer initialization, when trusted report for certain report types are generated. |
| Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE. |
| Memory corruption in HLOS while checking for the storage type. |
| Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem. |
| Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers. |
| Memory corruption while invoking IOCTLs calls in Automotive Multimedia. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE. |
| Transient DOS in Audio when invoking callback function of ASM driver. |
| Information disclosure in Audio while accessing AVCS services from ADSP payload. |
| Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command. |
| Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
| Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point. |
| Memory corruption while copying the result to the transmission queue which is shared between the virtual machine and the host. |
| Memory corruption in Core when updating rollback version for TA and OTA feature is enabled. |
| Memory corruption in Automotive Multimedia due to improper access control in HAB. |
| Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend. |