| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests. |
| Memory corruption while operating the mailbox in Automotive. |
| Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received. |
| Memory Corruption in WLAN HOST while processing WLAN FW request to allocate memory. |
| Memory corruption while processing IOCTL call for getting group info. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Memory corruption in BT controller while parsing debug commands with specific sub-opcodes at HCI interface level. |
| Memory corruption while processing concurrent IOCTL calls. |
| Transient DOS while parsing probe response and assoc response frame. |
| Memory corruption when multiple listeners are being registered with the same file descriptor. |
| Memory Corruption in Modem due to double free while parsing the PKCS15 sim files. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application. |
| While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper. |
| Memory corruption while processing finish_sign command to pass a rsp buffer. |
| Memory corruption while verifying the serialized header when the key pairs are generated. |
| Transient DOS may occur while processing the country IE. |
| Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length. |