CVE-2019-14055

EUVD-2019-5312
Possibility of use-after-free and double free because of not marking buffer as NULL after freeing can lead to dangling pointer access in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8939, MSM8953, MSM8996AU, MSM8998, Nicobar, QCN7605, QCS605, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX24, SDX55, SM8150, SM8250, SXR1130, SXR2130
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 10%
Affected Products (NVD)
VendorProductVersion
qualcommapq8009_firmware
-
qualcommapq8017_firmware
-
qualcommapq8053_firmware
-
qualcommapq8096au_firmware
-
qualcommapq8098_firmware
-
qualcommmdm9206_firmware
-
qualcommmdm9207c_firmware
-
qualcommmdm9607_firmware
-
qualcommmdm9640_firmware
-
qualcommmdm9650_firmware
-
qualcommmsm8905_firmware
-
qualcommmsm8909w_firmware
-
qualcommmsm8939_firmware
-
qualcommmsm8953_firmware
-
qualcommmsm8996au_firmware
-
qualcommmsm8998_firmware
-
qualcommnicobar_firmware
-
qualcommqcn7605_firmware
-
qualcommqcs605_firmware
-
qualcommsc8180x_firmware
-
qualcommsda660_firmware
-
qualcommsda845_firmware
-
qualcommsdm429_firmware
-
qualcommsdm429w_firmware
-
qualcommsdm439_firmware
-
qualcommsdm450_firmware
-
qualcommsdm630_firmware
-
qualcommsdm632_firmware
-
qualcommsdm636_firmware
-
qualcommsdm660_firmware
-
qualcommsdm845_firmware
-
qualcommsdx20_firmware
-
qualcommsdx24_firmware
-
qualcommsdx55_firmware
-
qualcommsm8150_firmware
-
qualcommsm8250_firmware
-
qualcommsxr1130_firmware
-
qualcommsxr2130_firmware
-
𝑥
= Vulnerable software versions