Where
-Infinity
0
Severity
5.5
Infoleak
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Information disclosure when a weak hashed value is returned to userland code in response to a IOCTL call to obtain a session ID.

First published (updated )
Severity
6.6
Use After Free
AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

Memory corruption while handling buffer mapping operations in the cryptographic driver.

First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Transient DOS while parsing video packets received from the video firmware.

First published (updated )
Severity
6.1
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

Information disclosure while processing a firmware event.

First published (updated )
Severity
8.8
Integer Overflow
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption when decoding corrupted satellite data files with invalid signature offsets.

First published (updated )
Severity
7.8
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.

First published (updated )
Severity
7.5
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS when processing target power rate tables during channel configuration.

First published (updated )
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Information disclosure while deriving keys for a session for any Widevine use case.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS may occur while processing the country IE.

First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS may occur while parsing SSID in action frames.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.

First published (updated )
Severity
7.8
Use After Free
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while handling file descriptor during listener registration/de-registration.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to write null character at the end of buffer.

First published (updated )
Severity
7.8
Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential failures occur.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while reading the FW response from the shared queue.

First published (updated )
Severity
7.8
Buffer Overflow
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS while processing received beacon frame.

First published (updated )
Severity
9.1
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Cryptographic issue occurs due to use of insecure connection method while downloading.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing video packets received from video firmware.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing manipulated payload in video firmware.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS may occur while processing malformed length field in SSID IEs.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS while processing an ANQP message.

First published (updated )
Severity
7.5
Input Validation
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS while processing CCCH data when NW sends data with invalid length.

First published (updated )
Severity
6.5
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Information disclosure while processing the hash segment in an MBN file.

First published (updated )
Severity
6.5
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Information disclosure while reading data from an image using specified offset and size parameters.

First published (updated )
Severity
9.8
Out-of-bounds Read
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while selecting the PLMN from SOR failed list.

First published (updated )
Severity
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Transient DOS while parsing the EPTM test control message to get the test pattern.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while performing private key encryption in trusted application.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203