Possible out of bound access in audio module due to lack of validation of user provided input.
Memory corruption in WLAN HAL while handling command streams through WMI interfaces.
Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.
Memory corruption while handling payloads from remote ESL.
Transient DOS in Modem while processing invalid System Information Block 1.
Memory corruption in Graphics while processing user packets for command submission.
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Memory Corruption in Core due to incorrect type conversion or cast in secureioread/write function in TEE.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Memory corruption while allocating memory in COmxApeDec module in Audio.
Memory Corruption in WLAN HOST while fetching TX status information.
Memory Corruption in Audio while allocating the ion buffer during the music playback.
Arbitrary memory overwrite when VM gets compromised in TX write leading to Memory Corruption.
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
Memory corruption in WLAN due to use after free
Memory corruption in Bluetooth HOST while processing the AVRCPDUGETPLAYERAPPVALUETEXT AVRCP response.
Memory corruption in modem due to use of out of range pointer offset while processing qmi msg
Transient DOS due to reachable assertion in modem when network repeatedly sent invalid message container for NR to LTE handover.
Memory corruption in Modem due to usage of Out-of-range pointer offset in UIM
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
Transient DOS due to reachable assertion in Modem while processing SIB1 Message.
Memory corruption in modem due to integer overflow to buffer overflow while handling APDU response
Memory corruption due to improper validation of array index in Multi-mode call processor.
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.