CVE-2019-10604

EUVD-2019-2408
Possibility of heap-buffer-overflow during last iteration of loop while populating image version information in diag command response packet, in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, MDM9607, MDM9640, MSM8909W, MSM8917, MSM8953, Nicobar, QCS605, QM215, Rennell, SA6155P, Saipan, SDA660, SDM429, SDM439, SDM450, SDM632, SDM670, SDM710, SDM845, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
qualcommapq8053_firmware
-
qualcommapq8096au_firmware
-
qualcommapq8098_firmware
-
qualcommmdm9607_firmware
-
qualcommmdm9640_firmware
-
qualcommmsm8909w_firmware
-
qualcommmsm8917_firmware
-
qualcommmsm8953_firmware
-
qualcommnicobar_firmware
-
qualcommqcs605_firmware
-
qualcommqm215_firmware
-
qualcommrennell_firmware
-
qualcommsa6155p_firmware
-
qualcommsaipan_firmware
-
qualcommsda660_firmware
-
qualcommsdm429_firmware
-
qualcommsdm439_firmware
-
qualcommsdm450_firmware
-
qualcommsdm632_firmware
-
qualcommsdm670_firmware
-
qualcommsdm710_firmware
-
qualcommsdm845_firmware
-
qualcommsm6150_firmware
-
qualcommsm7150_firmware
-
qualcommsm8150_firmware
-
qualcommsm8250_firmware
-
qualcommsxr1130_firmware
-
qualcommsxr2130_firmware
-
𝑥
= Vulnerable software versions