226 known vulnerabilities · sorted by CVSS score
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
Memory corruption in Core while processing control functions.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
Memory corruption in HLOS while running playready use-case.
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
Memory Corruption in Core due to secure memory access by user while loading modem image.
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
Memory corruption when processing cmd parameters while parsing vdev.
Memory corruption while invoking IOCTLs calls from user space for internal mem MAP and internal mem UNMAP.
Memory corruption in Audio while processing RT proxy port register driver.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory corruption in DSP Service during a remote call from HLOS to DSP.
Memory corruption when two threads try to map and unmap a single node simultaneously.