CVE-2019-10496

EUVD-2019-2300
Lack of checking a variable received from driver and populating in Firmware data structure leads to buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
qualcommmsm8909w_firmware
-
qualcommmsm8996au_firmware
-
qualcommqcs605_firmware
-
qualcommqualcomm_215_firmware
-
qualcommsd_210_firmware
-
qualcommsd_212_firmware
-
qualcommsd_205_firmware
-
qualcommsd_425_firmware
-
qualcommsd_427_firmware
-
qualcommsd_430_firmware
-
qualcommsd_435_firmware
-
qualcommsd_439_firmware
-
qualcommsd_429_firmware
-
qualcommsd_450_firmware
-
qualcommsd_625_firmware
-
qualcommsd_632_firmware
-
qualcommsd_636_firmware
-
qualcommsd_665_firmware
-
qualcommsd_675_firmware
-
qualcommsd_712_firmware
-
qualcommsd_710_firmware
-
qualcommsd_670_firmware
-
qualcommsd_730_firmware
-
qualcommsd_820_firmware
-
qualcommsd_820a_firmware
-
qualcommsd_835_firmware
-
qualcommsd_845_firmware
-
qualcommsd_850_firmware
-
qualcommsd_855_firmware
-
qualcommsd_8cx_firmware
-
qualcommsda660_firmware
-
qualcommsdm439_firmware
-
qualcommsdm630_firmware
-
qualcommsdm660_firmware
-
qualcommsnapdragon_high_med_2016_firmware
-
qualcommsxr1130_firmware
-
𝑥
= Vulnerable software versions