65 known vulnerabilities · sorted by CVSS score
Memory corruption while processing MBSSID beacon containing several subelement IE.
Memory corruption while redirecting log file to any file location with any file name.
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
Memory corruption while parsing the ML IE due to invalid frame content.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption in Core while processing control functions.
Memory corruption while processing TPC target power table in FTM TPC.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Memory corruption during management frame processing due to mismatch in T2LM info element.
Memory corruption may occour occur when stopping the WLAN interface after processing a WMI command from the interface.
Memory corruption when allocating and accessing an entry in an SMEM partition.
Memory corruption while processing video packets received from video firmware.
Memory corruption while processing command in Glink linux.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
Transient DOS while parse fils IE with length equal to 1.