46 known vulnerabilities · sorted by CVSS score
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory corruption in HLOS while running playready use-case.
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
Memory corruption when there is failed unmap operation in GPU.
A race condition exists in a driver potentially leading to a use-after-free condition.
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption in Audio while processing RT proxy port register driver.
Memory corruption in Audio during playback with speaker protection.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory corruption in Graphics while importing a file.
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet.
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
Information disclosure due to buffer over-read in Modem while parsing DNS hostname.
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length.
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.