Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Cryptographic issue while performing RSA PKCS padding decoding.
information disclosure while invoking calibration data from user space to update firmware size.
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
Memory corruption while processing a packet with a size close to the maximum allowed value.
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
Memory Corruption when handling malformed request parameters in the fingerprint TA.
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization.
Information Disclosure when processing advertisement frames with malformed MBSSID elements of insufficient length.
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
Memory corruption while processing fastboot commands with invalid input.
Memory Corruption when processing display command line information due to improper initialization of a variable.
Memory corruption while processing fastboot OEM commands.
Memory corruption while processing fastboot commands with improperly formatted input.
Memory Corruption when processing fastboot commands to set display mode.
Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
Transient DOS while processing received beacon frame.
Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the video firmware.
Transient DOS while handling beacon frames with invalid IE header length.
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.
Memory corruption while retrieving the CBOR data from TA.
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.