23 known vulnerabilities · sorted by CVSS score
Memory corruption in Core Services while executing the command for removing a single event listener.
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
Memory corruption when there is failed unmap operation in GPU.
Memory corruption in Audio while processing RT proxy port register driver.
Memory corruption while processing finish_sign command to pass a rsp buffer.
Memory corruption when two threads try to map and unmap a single node simultaneously.
Memory corruption in SPS Application while requesting for public key in sorter TA.
Information disclosure in Video while parsing mp2 clip with invalid section length.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Memory corruption when user provides data for FM HCI command control operations.
Memory corruption while retrieving the CBOR data from TA.
Memory corruption while reading secure file.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption when the payload received from firmware is not as per the expected protocol size.
Memory corruption while processing video packets received from video firmware.
Transient DOS while processing received beacon frame.
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
Transient DOS may occur while processing malformed length field in SSID IEs.