82 known vulnerabilities · sorted by CVSS score
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
Memory corruption in WLAN Host while processing RRM beacon on the AP.
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
Memory corruption due to double free in core while initializing the encryption key.
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.
Memory corruption in core services when Diag handler receives a command to configure event listeners.
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
Memory corruption in HLOS while invoking IOCTL calls from user-space.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory corruption due to improper validation of array index in Audio.
Memory corruption in Kernel while parsing metadata.
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
Memory corruption in Audio when SSR event is triggered after music playback is stopped.
Memory corruption in DSP Service during a remote call from HLOS to DSP.
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.