CVE-2024-38426
- EPSS 0.06%
- Published 03.03.2025 11:15:11
- Last modified 11.08.2025 15:06:17
While processing the authentication message in UE, improper authentication may lead to information disclosure.
CVE-2024-38416
- EPSS 0.02%
- Published 03.02.2025 17:15:17
- Last modified 05.02.2025 13:58:16
Information disclosure during audio playback.
CVE-2024-45555
- EPSS 0.03%
- Published 06.01.2025 11:15:10
- Last modified 13.01.2025 21:51:26
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.
CVE-2024-33067
- EPSS 0.03%
- Published 06.01.2025 11:15:08
- Last modified 11.08.2025 15:06:17
Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.
CVE-2017-11076
- EPSS 0.11%
- Published 26.11.2024 09:15:04
- Last modified 09.01.2025 21:02:48
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
CVE-2024-38423
- EPSS 0.04%
- Published 04.11.2024 10:15:09
- Last modified 07.11.2024 19:46:41
Memory corruption while processing GPU page table switch.
CVE-2024-38422
- EPSS 0.04%
- Published 04.11.2024 10:15:08
- Last modified 07.11.2024 19:45:57
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-33052
- EPSS 0.04%
- Published 02.09.2024 12:15:18
- Last modified 11.08.2025 15:06:17
Memory corruption when user provides data for FM HCI command control operations.
CVE-2024-33060
- EPSS 0.02%
- Published 02.09.2024 12:15:18
- Last modified 11.08.2025 15:06:17
Memory corruption when two threads try to map and unmap a single node simultaneously.
CVE-2024-33051
- EPSS 0.17%
- Published 02.09.2024 12:15:17
- Last modified 11.08.2025 15:06:17
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.