10 known vulnerabilities · sorted by CVSS score
Memory Corruption in Audio while allocating the ion buffer during the music playback.
Memory corruption when Alternative Frequency offset value is set to 255.
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
Transient DOS may occur while processing the country IE.
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
While processing the authentication message in UE, improper authentication may lead to information disclosure.