161 known vulnerabilities · sorted by CVSS score
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
Memory corruption in Core while processing control functions.
Memory corruption due to double free in core while initializing the encryption key.
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
Memory corruption in HLOS while running playready use-case.
Memory corruption in core services when Diag handler receives a command to configure event listeners.
Improper Access to the VM resource manager can lead to Memory Corruption.
Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.
Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.
Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND.
Memory corruption when resource manager sends the host kernel a reply message with multiple fragments.
Memory corruption in DSP Service during a remote call from HLOS to DSP.
Memory corruption while handling user packets during VBO bind operation.
Memory Corruption in HLOS while registering for key provisioning notify.
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
Memory corruption when processing cmd parameters while parsing vdev.
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.