Memory corruption due to buffer over-read in Modem while processing SetNativeHandle RTP service.
Memory corruption due to improper validation of array index in Audio.
Memory Corruption due to improper validation of array index in Linux while updating adn record.
Memory corruption in RIL due to Integer Overflow while triggering qcril_uim_request_apdu request.
Memory corruption in Audio during playback session with audio effects enabled.
Memory corruption in Audio while validating and mapping metadata.
Memory corruption in Core Platform while printing the response buffer in log.
Memory Corruption while accessing metadata in Display.
Memory Corruption in Core Platform while printing the response buffer in log.
Transient DOS in Modem while processing invalid System Information Block 1.
Transient DOS in Modem while processing RRC reconfiguration message.
Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.
Information disclosure in Automotive multimedia due to buffer over-read.
Memory corruption in QESL while processing payload from external ESL device to firmware.
Memory corruption while allocating memory in COmxApeDec module in Audio.
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a w…
In the function call related to CAM_REQ_MGR_RELEASE_BUF there is no check if the buffer is being used. So when a function called cam_mem_get_cpu_buf …
Transient DOS in Audio while remapping channel buffer in media codec decoding.
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, us…
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
Memory corruption due to untrusted pointer dereference in automotive during system call.
Memory corruption in RIL while trying to send apdu packet.
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.