Memory Corruption when multiple threads simultaneously access a memory free API.
Transient DOS while processing received beacon frame.
Transient DOS may occur while processing malformed length field in SSID IEs.
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
Transient DOS while loading the TA ELF file.
Memory corruption when the channel ID passed by user is not validated and further used.
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
Memory corruption in Core Services while executing the command for removing a single event listener.
Transient DOS while converting TWT (Target Wake Time) frame parameters in the OTA broadcast.
Transient DOS while parsing a vender specific IE (Information Element) of reassociation response management frame.
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
Transient DOS in Modem while allocating DSM items.
Transient DOS in WLAN Firmware while parsing rsn ies.
Improper Access to the VM resource manager can lead to Memory Corruption.
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
Memory corruption in WLAN HAL while handling command through WMI interfaces.
Memory corruption due to improper validation of array index in WLAN HAL when received lmitemNum is out of range.
Memory corruption in WLAN HAL while parsing WMI command parameters.
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
information disclosure due to cryptographic issue in Core during RPMB read request.
Transient DOS in WLAN Firmware while processing frames with missing header fields.
Transient DOS due to improper authorization in Modem
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.