Information Disclosure in Data Modem while performing a VoLTE call with an undefined RTCP FB line value.
Information Disclosure in data Modem while parsing an FMTP line in an SDP message.
Memory Corruption in HLOS while importing a cryptographic key into KeyMaster Trusted Application.
Memory Corruption in HLOS while registering for key provisioning notify.
Memory corruption in Modem while processing security related configuration before AS Security Exchange.
Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks for services that require an active session.
Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.
All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.
Memory corruption in WLAN Host when the firmware invokes multiple WMI Service Available command.
Cryptographic issue in Data Modem due to improper authentication during TLS handshake.