Where
AND
-Infinity
0
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption when non-secure loader rewrites page tables before secure memory initialization.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing control commands in the virtual memory management interface.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing a malformed license file during reboot.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption during PlayReady APP usecase while processing TA commands.

First published (updated )
Severity
7.8
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.

First published (updated )
Severity
7.8
Integer Overflow
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while routing GPR packets between user and root when handling large data packet.

First published (updated )
Severity
7.9
Infoleak
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Information disclosure may occur due to improper permission and access controls to Video Analytics engine.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS may occur while processing the country IE.

First published (updated )
Severity
7.8
Out-of-bounds Read
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption may occur while validating ports and channels in Audio driver.

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS may occur while parsing SSID in action frames.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.

First published (updated )
Severity
7.5
AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.

First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesnt adhere to RFC standards.

First published (updated )
Severity
7.8
Use After Free
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while handling file descriptor during listener registration/de-registration.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while reading secure file.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.

First published (updated )
Severity
7.8
Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.

First published (updated )
Severity
7.8
Out-of-bounds Read
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN HAL while parsing WMI command parameters.

First published (updated )
Severity
7.8
Buffer Overflow
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.

First published (updated )
Severity
8.4
Use After Free
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption in Graphics while processing user packets for command submission.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS while processing received beacon frame.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.

First published (updated )
Severity
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.

First published (updated )
Severity
7.8
Double Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while retrieving the CBOR data from TA.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing video packets received from video firmware.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS may occur while processing malformed length field in SSID IEs.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203