CVE-2019-2302

EUVD-2019-11944
While processing vendor command which contains corrupted channel count, an integer overflow occurs and finally will lead to heap overflow. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8017, APQ8053, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8976, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCN7605, QCS405, QCS605, SDA845, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SDX24, SM6150, SM8150
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
qualcommapq8017_firmware
-
qualcommapq8053_firmware
-
qualcommapq8096au_firmware
-
qualcommmdm9206_firmware
-
qualcommmdm9207c_firmware
-
qualcommmdm9607_firmware
-
qualcommmdm9640_firmware
-
qualcommmdm9650_firmware
-
qualcommmsm8905_firmware
-
qualcommmsm8909_firmware
-
qualcommmsm8909w_firmware
-
qualcommmsm8976_firmware
-
qualcommmsm8996au_firmware
-
qualcommqca6174a_firmware
-
qualcommqca6574au_firmware
-
qualcommqca9377_firmware
-
qualcommqca9379_firmware
-
qualcommqcn7605_firmware
-
qualcommqcs405_firmware
-
qualcommqcs605_firmware
-
qualcommsda845_firmware
-
qualcommsdm636_firmware
-
qualcommsdm660_firmware
-
qualcommsdm670_firmware
-
qualcommsdm710_firmware
-
qualcommsdm845_firmware
-
qualcommsdx20_firmware
-
qualcommsdx24_firmware
-
qualcommsm6150_firmware
-
qualcommsm8150_firmware
-
𝑥
= Vulnerable software versions