Possible out of bound access in audio module due to lack of validation of user provided input.
Memory corruption in Audio during playback session with audio effects enabled.
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
Memory corruption due to untrusted pointer dereference in automotive during system call.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Memory corruption in WLAN due to use after free
Memory corruption in WLAN due to incorrect type cast while sending WMISCANSCHPRIOTBLCMDID message.
Memory corruption in Bluetooth HOST while processing the AVRCPDUGETPLAYERAPPVALUETEXT AVRCP response.
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
Memory corruption in modem due to buffer overflow while processing a PPP packet
Information Disclosure in Graphics during GPU context switch.
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
Memory corruption in Audio due to use of out-of-range pointer offset while Initiating a voice call session from user space with invalid session id.
Memory corruption due to use after free in trusted application environment.
Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.
Memory corruption due to improper access control in Qualcomm IPC.
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
Memory corruption due to stack-based buffer overflow in Core
Transient DOS due to null pointer dereference in Bluetooth HOST while receiving an attribute protocol PDU with zero length data.
Transient DOS in Bluetooth HOST due to null pointer dereference when a mismatched argument is passed.
Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer.
Memory corruption in Automotive due to improper input validation.
Information exposure in DSP services due to improper handling of freeing memory
Memory corruption in display due to double free while allocating frame buffer memory
Denial of service while processing fastboot flash command on mmc due to buffer over read