Memory corruption while selecting the PLMN from SOR failed list.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Cryptographic issue occurs due to use of insecure connection method while downloading.
Memory corruption during management frame processing due to mismatch in T2LM info element.
Memory corruption while parsing the ML IE due to invalid frame content.
Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.
Memory corruption while redirecting log file to any file location with any file name.
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Memory corruption while redirecting log file to any file location with any file name.
Memory corruption while processing MBSSID beacon containing several subelement IE.
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
Memory corruption in Core Services while executing the command for removing a single event listener.
Memory corruption in Core while processing control functions.
Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.
Memory corruption in HLOS while running playready use-case.
Memory corruption in WLAN Host while processing RRM beacon on the AP.
Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory Corruption in Data Modem while making a MO call or MT VOLTE call.
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Memory corruption while handling payloads from remote ESL.
Memory Corruption in Core due to incorrect type conversion or cast in secureioread/write function in TEE.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
Memory corruption due to double free in core while initializing the encryption key.
Memory corruption due to buffer copy without checking the size of input in Core while sending SCM command to get write protection information.
Memory corruption due to integer overflow or wraparound in Core while DDR memory assignment.
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.