227 known vulnerabilities · sorted by CVSS score
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
Memory corruption while parsing the ML IE due to invalid frame content.
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Memory corruption while processing MBSSID beacon containing several subelement IE.
Memory corruption in Core Services while executing the command for removing a single event listener.
Cryptographic issue occurs due to use of insecure connection method while downloading.
Memory Corruption when a corrupted ELF image with an oversized file size is read into a buffer without authentication.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.
Memory corruption while processing finish_sign command to pass a rsp buffer.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
Memory corruption when processing cmd parameters while parsing vdev.
Memory corruption when two threads try to map and unmap a single node simultaneously.