27 known vulnerabilities · sorted by CVSS score
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
Memory corruption while configuring a Hypervisor based input virtual device.
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
Memory corruption while processing finish_sign command to pass a rsp buffer.
Memory corruption in SPS Application while requesting for public key in sorter TA.
Memory corruption when there is failed unmap operation in GPU.
Memory corruption in Audio while processing RT proxy port register driver.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Memory corruption while retrieving the CBOR data from TA.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption while processing video packets received from video firmware.
Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.
Memory corruption while reading secure file.
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
Memory corruption when the payload received from firmware is not as per the expected protocol size.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
Transient DOS may occur while processing malformed length field in SSID IEs.