Memory corruption in Trusted Execution Environment while calling service API with invalid address.
Memory corruption due to untrusted pointer dereference in automotive during system call.
Memory corruption in RIL while trying to send apdu packet.
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
Weak Configuration due to improper input validation in Modem while processing LTE security mode command message received from network.
Memory Corruption in Linux while processing QcRilRequestImsRegisterMultiIdentityMessage request.
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
Memory corruption in Linux while calling system configuration APIs.
Memory corruption in Video while calling APIs with different instance ID than the one received in initialization.
Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
Memory corruption in Linux when the file upload API is called with parameters having large buffer.
Memory Corruption in Audio while allocating the ion buffer during the music playback.
Memory Corruption in Modem due to double free while parsing the PKCS15 sim files.
Information disclosure in DSP Services while loading dynamic module.
Memory corruption in Automotive GPU while querying a gsl memory node.
Transient DOS in WLAN Firmware while processing the received beacon or probe response frame.
Transient DOS in WLAN Firmware while processing frames with missing header fields.
Transient DOS in WLAN Firmware while parsing FT Information Elements.
Transient DOS while parsing WLAN beacon or probe-response frame.
Memory corruption due to double free in Core while mapping HLOS address to the list.
Memory corruption in Linux Networking due to double free while handling a hyp-assign.
Memory corruption due to improper access control in kernel while processing a mapping request from root process.
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.
Transient DOS due to improper authorization in Modem