Possible out of bound access in audio module due to lack of validation of user provided input.
Memory corruption in Audio while processing the VOC packet data from ADSP.
Transient DOS in WLAN Firmware while parsing rsn ies.
A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted model (e.g. from a remote source).
Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.
Memory Corruption in Core Platform while printing the response buffer in log.
Memory corruption in Core Platform while printing the response buffer in log.
Memory Corruption in Core due to incorrect type conversion or cast in secureioread/write function in TEE.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Memory corruption while allocating memory in COmxApeDec module in Audio.
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.
Memory corruption in Graphics while importing a file.
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
Memory corruption due to integer overflow to buffer overflow in Modem while parsing Traffic Channel Neighbor List Update message.
Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming.
Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
Memory corruption due to double free in core while initializing the encryption key.
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length.
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
Memory corruption in WLAN due to incorrect type cast while sending WMISCANSCHPRIOTBLCMDID message.
Memory corruption in Bluetooth HOST while processing the AVRCPDUGETPLAYERAPPVALUETEXT AVRCP response.
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.