Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet.
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
Memory corruption during PlayReady APP usecase while processing TA commands.
Memory corruption while using alignments for memory allocation.
Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.
Memory corruption in DSP Services during a remote call from HLOS to DSP.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Memory Corruption in SPS Application while exporting public key in sorter TA.
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesnt adhere to RFC standards.
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption in Audio while processing the VOC packet data from ADSP.
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.
Memory corruption while processing voice packet with arbitrary data received from ADSP.
Memory corruption while processing GPU page table switch.
Memory corruption in HLOS while running playready use-case.
The session index variable in PCM host voice audio driver initialized before PCM open, accessed during event callback from ADSP and reset during PCM close may lead to race condition between event callback - PCM close and reset session index causing memory corruption.
Memory corruption in Audio during playback with speaker protection.
Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESMIEI.
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
information disclosure due to cryptographic issue in Core during RPMB read request.
Transient DOS due to improper authorization in Modem
Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message.