Memory corruption in RIL while trying to send apdu packet.
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
Memory Corruption in GPS HLOS Driver when injectFdclData receives data with invalid data length.
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Information disclosure in Network Services due to buffer over-read while the device receives DNS response.
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability could allow a local attacker to execute code with elevated privileges by placing a malicious DLL in one of the directories on the DLL search path.
A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). Affected applications do not properly set permissions for product folders. This could allow an authenticated attacker with low privileges to replace DLLs and conduct a privilege escalation.