Possible out of bound access in audio module due to lack of validation of user provided input.
Memory corruption in Audio while processing the VOC packet data from ADSP.
Transient DOS in WLAN Firmware while parsing rsn ies.
A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted model (e.g. from a remote source).
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
Memory Corruption in Core Platform while printing the response buffer in log.
Memory corruption in Core Platform while printing the response buffer in log.
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.
Memory corruption in Graphics while importing a file.
Memory corruption due to double free in core while initializing the encryption key.
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
Memory corruption in WLAN due to incorrect type cast while sending WMISCANSCHPRIOTBLCMDID message.
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
Memory corruption in modem due to buffer overflow while processing a PPP packet
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.
Memory corruption due to access of uninitialized pointer in Bluetooth HOST while processing the AVRCP packet.
Memory corruption due to improper access control in Qualcomm IPC.
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
Information disclosure due to buffer overread in Core
Memory corruption in core due to stack-based buffer overflow
Memory corruption in Core due to stack-based buffer overflow.
Transient DOS due to buffer over-read in WLAN while parsing WLAN CSA action frames.