| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data. |
| Information disclosure in Video while parsing mp2 clip with invalid section length. |
| Information Disclosure in data Modem while parsing an FMTP line in an SDP message. |
| Memory corruption in MPP performance while accessing DSM watermark using external memory address. |
| Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size. |
| Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption. |
| While processing the authentication message in UE, improper authentication may lead to information disclosure. |
| Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size. |
| Memory Corruption in Audio while allocating the ion buffer during the music playback. |
| Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element. |
| Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus. |
| Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. |
| Information Disclosure in Qualcomm IPC while reading values from shared memory in VM. |
| Transient DOS while processing TIM IE from beacon frame as there is no check for IE length. |
| Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value. |
| Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network. |
| Information disclosure when the trusted application metadata symbol addresses are accessed while loading an ELF in TEE. |
| Memory corruption while using the UIM diag command to get the operators name. |
| Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains `IPPROTO_NONE` as the next header. |
| Memory corruption when the payload received from firmware is not as per the expected protocol size. |