Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
Memory corruption while processing fastboot commands with improperly formatted input.
Memory Corruption when processing display command line information due to improper initialization of a variable.
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and deallocation of buffer resources.
Memory corruption while handling buffer mapping operations in the cryptographic driver.
Transient DOS while parsing video packets received from the video firmware.
Memory corruption while processing MFC channel configuration during music playback.
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
Memory corruption while processing a malformed license file during reboot.
Memory corruption during PlayReady APP usecase while processing TA commands.
Transient DOS while parsing the EPTM test control message to get the test pattern.
Memory corruption while performing private key encryption in trusted application.
Cryptographic issue while performing RSA PKCS padding decoding.
Transient DOS while processing an ANQP message.
Information disclosure while processing the hash segment in an MBN file.
Information disclosure while reading data from an image using specified offset and size parameters.
Memory corruption while processing video packets received from video firmware.
Transient DOS while processing received beacon frame.
Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.
Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.
Transient DOS may occur while parsing SSID in action frames.
Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.
Memory corruption while handling file descriptor during listener registration/de-registration.
Memory corruption while parsing the memory map info in IOCTL calls.
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
Memory corruption while processing voice packet with arbitrary data received from ADSP.