Show filters
607 Total Results
Displaying 181-190 of 607
Sort by:
Attacker Value
Unknown

CVE-2023-28576

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
The buffer obtained from kernel APIs such as cam_mem_get_cpu_buf() may be readable/writable in userspace after kernel accesses it. In other words, user mode may race and modify the packet header (e.g. header.count), causing checks (e.g. size checks) in kernel code to be invalid. This may lead to out-of-bounds read/write issues.
Attacker Value
Unknown

CVE-2023-28575

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
The cam_get_device_priv function does not check the type of handle being returned (device/session/link). This would lead to invalid type usage if a wrong handle is passed to it.
Attacker Value
Unknown

CVE-2023-28537

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory corruption while allocating memory in COmxApeDec module in Audio.
Attacker Value
Unknown

CVE-2023-22666

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Attacker Value
Unknown

CVE-2023-21652

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Attacker Value
Unknown

CVE-2023-21651

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
Attacker Value
Unknown

CVE-2023-21650

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
Attacker Value
Unknown

CVE-2023-21649

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
Attacker Value
Unknown

CVE-2023-21647

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Information disclosure in Bluetooth when an GATT packet is received due to improper input validation.
Attacker Value
Unknown

CVE-2023-21627

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory corruption in Trusted Execution Environment while calling service API with invalid address.