Where
-Infinity
0
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while IOCTL call is invoked from user-space to read board data.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing voice packet with arbitrary data received from ADSP.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing GPU page table switch.

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS while parsing IPv6 extension header when WLAN firmware receives an IPv6 packet that contains IPPROTONONE as the next header.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption in Audio during playback with speaker protection.

First published (updated )
Severity
7.8
Buffer Overflow
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in MPP performance while accessing DSM watermark using external memory address.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.

First published (updated )
Severity
7.8
Integer Underflow
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in Audio while processing the VOC packet data from ADSP.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory Corruption in Data Modem while making a MO call or MT VOLTE call.

First published (updated )
Severity
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.

First published (updated )
Severity
7.8
Out-of-bounds Read
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN HAL while handling command streams through WMI interfaces.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS due to improper authorization in Modem

First published (updated )
Severity
8.4
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.

First published (updated )
Severity
7.9
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.

First published (updated )
Severity
8.4
Incorrect Type Cast
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in Graphics while importing a file.

First published (updated )
Severity
8.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.

First published (updated )
Severity
6.8
Out-of-bounds Read
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.

First published (updated )
Severity
8.4
Integer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.

First published (updated )
Severity
7.8
Out-of-bounds Read
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.

First published (updated )
Severity
8.4
Incorrect Type Cast
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN due to incorrect type cast while sending WMISCANSCHPRIOTBLCMDID message.

First published (updated )
Severity
8.4
Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM

First published (updated )
Severity
7.8
Buffer Overflow, Integer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response

First published (updated )
Severity
8.8
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in modem due to buffer overflow while processing a PPP packet

First published (updated )
Severity
8.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption due to configuration weakness in modem wile sending command to write protected files.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203