8.4
CVE-2024-33044 - Improper Validation of Array Index in Hypervisor
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
6.7
CVE-2024-33040 - Use After Free in Camera Driver
Memory corruption while invoking redundant release command to release one buffer from user space as race condition can occur in kernel space between buffer release and buffer access.
6.7
CVE-2024-33039 - Untrusted Pointer Dereference in Audio
Memory corruption when PAL client calls PAL service APIs by passing a random value as handle and the handle is not validated by the service.
6.1
CVE-2024-33037 - Buffer Over-read in Neural Processing Unit
Information disclosure as NPU firmware can send invalid IPC message to NPU driver as the driver doesn`t validate the IPC message received from the firmware.
6.7
CVE-2024-33036 - Use of Out-of-range Pointer Offset in Camera Driver
Memory corruption while parsing sensor packets in camera driver, user-space variable is used while allocating memory in kernel and parsing which can lead to huge allocation or invalid memory access.
8.4
CVE-2024-10490 - Authentication bypass flaw in several mapp components
An βAuthentication Bypass Using an Alternate Path or Channelβ vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticateβ¦
6.5
CVE-2024-20139 -
In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001270; Issue ID: MSV-1600.
7.5
CVE-2024-20138 -
In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.
4.4
CVE-2024-20116 -
In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09057438; Issue ID: MSV-1696.
7.5
CVE-2024-20137 -
In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00384543; Issue ID: MSV-1727.