VDB

CVE-2019-10581

CVE-2019-10581 PUBLISHED CVSS 9.800000190734863 CRITICAL

NULL is assigned to local instance of audio device pointer after free instead of global static pointer and can lead to use after free issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, MDM9206, MDM9207C, MDM9607, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8998, Nicobar, QCS605, Rennell, SA6155P, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130

EPSS 0.39% · 60.1th percentile

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.39%
60.1th percentile

Affected Products

VendorProductVersions
Qualcomm, Inc.Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables*
qualcommsdx55_firmware
qualcommsm6150_firmware
qualcommsm8150_firmware
qualcommmsm8937_firmware
qualcommsdm670_firmware
qualcommsxr2130_firmware
qualcommmsm8909w_firmware
qualcommsdm845_firmware
qualcommqcs605_firmware
qualcommapq8009_firmware
qualcommsdm630_firmware
qualcommsdm660_firmware
qualcommsm7150_firmware
qualcommmsm8998_firmware
qualcommmsm8917_firmware
qualcommsm8250_firmware
qualcommrennell_firmware
qualcommnicobar_firmware
qualcommsa6155p_firmware

…and 9 more

Timeline

  • Jan 8, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 27, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 2, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›