CVE-2019-14080

EUVD-2019-5335
Out of bound write can happen due to lack of check of array index value while parsing SDP attribute for SAR in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, Kamorta, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, Nicobar, QCM2150, QCS605, QM215, Rennell, SA415M, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SM6150, SM7150, SM8150, SXR1130
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
Affected Products (NVD)
VendorProductVersion
qualcommapq8053_firmware
-
qualcommapq8096au_firmware
-
qualcommkamorta_firmware
-
qualcommmdm9607_firmware
-
qualcommmdm9640_firmware
-
qualcommmdm9650_firmware
-
qualcommmsm8905_firmware
-
qualcommmsm8909_firmware
-
qualcommmsm8917_firmware
-
qualcommmsm8920_firmware
-
qualcommmsm8937_firmware
-
qualcommmsm8940_firmware
-
qualcommmsm8953_firmware
-
qualcommmsm8996au_firmware
-
qualcommnicobar_firmware
-
qualcommqcm2150_firmware
-
qualcommqcs605_firmware
-
qualcommqm215_firmware
-
qualcommrennell_firmware
-
qualcommsa415m_firmware
-
qualcommsc7180_firmware
-
qualcommsc8180x_firmware
-
qualcommsda660_firmware
-
qualcommsda845_firmware
-
qualcommsdm429_firmware
-
qualcommsdm439_firmware
-
qualcommsdm450_firmware
-
qualcommsdm630_firmware
-
qualcommsdm632_firmware
-
qualcommsdm636_firmware
-
qualcommsdm660_firmware
-
qualcommsdm670_firmware
-
qualcommsdm710_firmware
-
qualcommsdm845_firmware
-
qualcommsdm850_firmware
-
qualcommsdx24_firmware
-
qualcommsm6150_firmware
-
qualcommsm7150_firmware
-
qualcommsm8150_firmware
-
qualcommsxr1130_firmware
-
𝑥
= Vulnerable software versions