Memory Corruption when multiple threads simultaneously access a memory free API.
Transient DOS while processing received beacon frame.
Transient DOS may occur while processing malformed length field in SSID IEs.
Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.
Transient DOS when importing a PKCS#8-encoded RSA private key with a zero-sized modulus.
Memory corruption while retrieving the CBOR data from TA.
Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.
Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.
Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.
Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.
Memory corruption while triggering commands in the PlayReady Trusted application.
Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.
Memory corruption during the FRS UDS generation process.
Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.
Memory corruption when the channel ID passed by user is not validated and further used.
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.
Memory corruption in Core Services while executing the command for removing a single event listener.
Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.