14 known vulnerabilities · sorted by CVSS score
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
Memory Corruption in Audio while allocating the ion buffer during the music playback.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
Memory corruption when user provides data for FM HCI command control operations.
Memory corruption when Alternative Frequency offset value is set to 255.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Transient DOS may occur while processing the country IE.
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
While processing the authentication message in UE, improper authentication may lead to information disclosure.