Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Memory Corruption in Core due to incorrect type conversion or cast in secureioread/write function in TEE.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Memory corruption while allocating memory in COmxApeDec module in Audio.
Memory Corruption in Multimedia Framework due to integer overflow when synx bind is called along with synx signal.
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
Memory corruption in WLAN due to incorrect type cast while sending WMISCANSCHPRIOTBLCMDID message.
Memory corruption in Bluetooth HOST while processing the AVRCPDUGETPLAYERAPPVALUETEXT AVRCP response.
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
Memory corruption in modem due to buffer overflow while processing a PPP packet
Transient DOS due to buffer over-read in WLAN while sending a packet to device.
Information Disclosure in Graphics during GPU context switch.
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
Memory corruption in User Identity Module due to integer overflow to buffer overflow when a segement is received via qmi http.
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
Transient DOS due to improper input validation in WLAN Host while parsing frame during defragmentation.
Transient DOS due to improper input validation in WLAN Host.
Information disclosure due to buffer overread in Core
Information disclosure due to buffer overread in Core