CVE-2019-10588 PUBLISHED CVSS 9.800000190734863 CRITICAL

Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote stack overflow. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8076, APQ8096, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCM2150, QCS605, QM215, Rennell, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130

EPSS 0.36% · 57.7th percentile

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.36%
57.7th percentile

Affected Products

VendorProductVersions
qualcommsm8150_firmware
qualcommsdx24_firmware
qualcommmdm9640_firmware
qualcommsc8180x_firmware
qualcommqcm2150_firmware
qualcommsda845_firmware
qualcommsdm632_firmware
qualcommmsm8909w_firmware
qualcommsxr1130_firmware
qualcommapq8017_firmware
qualcommsm6150_firmware
qualcommmdm9615_firmware
qualcommmsm8905_firmware
qualcommsdm660_firmware
qualcommmsm8953_firmware
qualcommsdm450_firmware
qualcommmdm9206_firmware
qualcommmdm9150_firmware
qualcommsdx20_firmware
qualcommapq8098_firmware

…and 35 more

Timeline

References

Open in Interactive Console →