Possible out of bound access in audio module due to lack of validation of user provided input.
A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted model (e.g. from a remote source).
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Memory Corruption in Core due to incorrect type conversion or cast in secureioread/write function in TEE.
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
Memory corruption in WLAN due to use after free
Memory corruption in WLAN due to incorrect type cast while sending WMISCANSCHPRIOTBLCMDID message.
Memory corruption in Bluetooth HOST while processing the AVRCPDUGETPLAYERAPPVALUETEXT AVRCP response.
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
Memory corruption in modem due to buffer overflow while processing a PPP packet
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
Information Disclosure in Graphics during GPU context switch.
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
Information disclosure due to buffer over-read in Modem while using static array to process IPv4 packets.
Information disclosure in modem due to buffer over-red while performing checksum of packet received
Denial of service in modem due to missing null check while processing TCP or UDP packets from server
Denial of service in modem due to missing null check while processing IP packets with padding
Denial of service in modem due to null pointer dereference while processing DNS packets
Information disclosure in modem due to buffer over read in dns client due to missing length check
Memory corruption in modem due to improper length check while copying into memory
Information disclosure in modem due to buffer over-read while processing response from DNS server
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.