497 known vulnerabilities · sorted by CVSS score
Memory corruption while parsing the ML IE due to invalid frame content.
Memory corruption in modem due to improper length check while copying into memory
Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.
Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.
Memory Corruption in Multi-mode Call Processor while processing bit mask API.
Memory corruption while selecting the PLMN from SOR failed list.
Memory corruption while processing MBSSID beacon containing several subelement IE.
Memory corruption in WLAN Firmware while parsing a NAN management frame carrying a S3 attribute.
Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.
Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length parameter in Snapdragon Connectivity, Snapdragon Mobile
Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.
Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile
Memory corruption in Hypervisor when platform information mentioned is not aligned.
Memory corruption in HLOS while running playready use-case.
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.