CVE-2019-10484

Use after free issue occurs when command destructors access dynamically allocated response buffer which is already deallocated during previous command teardwon sequence in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8098, MSM8909W, Nicobar, QCS405, QCS605, SDA845, SDM660, SDM670, SDM710, SDM845, SDX24, SM6150, SM7150, SM8150, SM8250, SXR2130
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
qualcommCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
VendorProductVersion
qualcommapq8098_firmware
-
qualcommmsm8909w_firmware
-
qualcommnicobar_firmware
-
qualcommqcs405_firmware
-
qualcommqcs605_firmware
-
qualcommsda845_firmware
-
qualcommsdm660_firmware
-
qualcommsdm670_firmware
-
qualcommsdm710_firmware
-
qualcommsdm845_firmware
-
qualcommsdx24_firmware
-
qualcommsm6150_firmware
-
qualcommsm7150_firmware
-
qualcommsm8150_firmware
-
qualcommsm8250_firmware
-
qualcommsxr2130_firmware
-
𝑥
= Vulnerable software versions