Where
AND
-Infinity
0
Severity
8.8
Incorrect Type Cast, Buffer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Possible buffer overflow to improper validation of hash segment of file while allocating memory in Snapdragon Connectivity, Snapdragon Mobile

First published (updated )
Severity
8.8
Input Validation
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Memory corruption while configuring a Hypervisor based input virtual device.

First published (updated )
Severity
8.8
Integer Overflow
AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption when decoding corrupted satellite data files with invalid signature offsets.

First published (updated )
Severity
8.8
Buffer Overflow
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Memory corruption while using Strongbox due to buffer overflow.

First published (updated )
Severity
8.8
Out-of-bounds Read
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Memory corruption while using Strongbox due to missing bounds check.

First published (updated )
Severity
8.8
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

First published (updated )
Severity
8.8
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in modem due to buffer overflow while processing a PPP packet

First published (updated )
Severity
8.8
Integer Overflow, Buffer Overflow
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

First published (updated )
Severity
8.8
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Buffer copy in GATT multi notification due to improper length check for the data coming over-the-air in Snapdragon Connectivity, Snapdragon Industrial IOT

First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption in WLAN HOST while processing the WLAN scan descriptor list.

First published (updated )
Severity
8.8
Buffer Overflow
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Memory corruption while loading an ELF segment in TEE Kernel.

First published (updated )
Severity
8.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Improper Access to the VM resource manager can lead to Memory Corruption.

First published (updated )
Severity
8.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

1 / 2
Source: MITRE
First published (updated )
Severity
8.6
AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

1 / 2
Source: MITRE
First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption in Audio during playback with speaker protection.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while reading ACPI config through the user mode app.

First published (updated )
Severity
8.4
Out-of-bounds Read
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.

First published (updated )
Severity
8.4
Null Pointer Dereference
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while invoking the SubmitCommands call on Gfx engine during the graphics render.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing TPC target power table in FTM TPC.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while processing the IOCTL FM HCI WRITE request.

First published (updated )
Severity
8.4
Integer Overflow
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while allocating memory for graphics.

First published (updated )
Severity
8.4
Use After Free
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption in Kernel while handling GPU operations.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption when size of buffer from previous call is used without validation or re-initialization.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.

First published (updated )
Severity
8.4
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.

First published (updated )
Severity
8.4
Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.

First published (updated )
Severity
8.4
Use After Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while handling user packets during VBO bind operation.

First published (updated )
Severity
8.4
Double Free
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while performing finish HMAC operation when context is freed by keymaster.

First published (updated )
Severity
8.4
Integer Overflow
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203