Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.
Memory Corruption in Core Platform while printing the response buffer in log.
Memory corruption in Core Platform while printing the response buffer in log.
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Memory Corruption in Core due to incorrect type conversion or cast in secureioread/write function in TEE.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
Memory corruption in WLAN due to incorrect type cast while sending WMISCANSCHPRIOTBLCMDID message.
Memory corruption in Bluetooth HOST while processing the AVRCPDUGETPLAYERAPPVALUETEXT AVRCP response.
Memory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.
Transient DOS due to reachable assertion in WLAN while processing PEER ID populated by TQM.
Memory corruption due to buffer copy without checking the size of input in HLOS when input message size is larger than the buffer capacity.
Memory corruption in WLAN due to integer overflow to buffer overflow in WLAN during initialization phase.
Information Disclosure in Graphics during GPU context switch.
Memory corruption due to improper authentication in Qualcomm IPC while loading unsigned lib in audio PD.
Transient DOS due to buffer over-read in WLAN Firmware while parsing secure FTMR frame with size lesser than 39 Bytes.
Memory corruption due to improper access control in Qualcomm IPC.
Information disclosure due to buffer over-read in WLAN while parsing NMF frame.
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
Transient DOS due to buffer over-read in WLAN Host while parsing frame information.
Memory corruption in modem due to buffer copy without checking size of input while receiving WMI command.
Transient DOS in WLAN Firmware due to buffer over-read while processing probe response or beacon.
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.
Transient DOS due to buffer over-read in WLAN while processing an incoming management frame with incorrectly filled IEs.
Transient DOS due to improper input validation in WLAN Host while parsing frame during defragmentation.
Transient DOS due to improper input validation in WLAN Host.
Memory corruption due to stack-based buffer overflow in Core
Information disclosure due to buffer overread in Core