CVE-2019-10607 PUBLISHED CVSS 7.800000190734863 HIGH

Out of bounds memcpy can occur by providing the embedded NULL character string and length greater than the actual string length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, IPQ4019, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9615, MDM9640, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8996, MSM8996AU, QCA4531, QCA8081, QCA9531, QCA9558, QCA9886, QCA9980, QCN7605, QCS605, SDA660, SDX20, SDX24, SDX55, SM8150, SXR1130

EPSS 0.03% · 9.5th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.03%
9.5th percentile

Affected Products

VendorProductVersions
qualcommqca9886_firmware
qualcommmdm9607_firmware
qualcommqca8081_firmware
qualcommmdm9615_firmware
qualcommmsm8909w_firmware
qualcommqca9558_firmware
qualcommqcs605_firmware
qualcommapq8098_firmware
qualcommmdm9650_firmware
qualcommmdm9206_firmware
qualcommmdm9640_firmware
qualcommsdx24_firmware
qualcommmsm8920_firmware
qualcommqcn7605_firmware
qualcommqca4531_firmware
qualcommapq8009_firmware
qualcommmsm8917_firmware
qualcommapq8096au_firmware
qualcommsxr1130_firmware
qualcommsdx55_firmware

…and 20 more

Timeline

References

Open in Interactive Console →