84 known vulnerabilities · sorted by CVSS score
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
Memory corruption in WLAN Host while processing RRM beacon on the AP.
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Memory corruption while redirecting log file to any file location with any file name.
Memory corruption while processing a GP command response.
Memory corruption while performing SCM call.
Memory corruption while performing SCM call with malformed inputs.
Memory corruption when processing cmd parameters while parsing vdev.
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
Memory corruption in Kernel while parsing metadata.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Memory corruption in DSP Services during a remote call from HLOS to DSP.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
Memory corruption in MPP performance while accessing DSM watermark using external memory address.