VDB
CVE-2019-14123
CVE-2019-14123
PUBLISHED
CVSS 7.800000190734863 HIGH
Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HLOS client as non-trustable in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130
EPSS 0.05% · 17.3th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.05%
17.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| qualcomm | sc7180_firmware | |
| qualcomm | sxr2130_firmware | |
| qualcomm | sm6150_firmware | |
| qualcomm | sm8250_firmware | |
| Qualcomm, Inc. | Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking | Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130 |
| qualcomm | qcs404_firmware | |
| qualcomm | sdx55_firmware | |
| qualcomm | rennell_firmware | |
| qualcomm | kamorta_firmware | |
| qualcomm | sm7150_firmware |
Exploit Intelligence
Timeline
- Jul 7, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
References
- https://source.android.com/security/bulletin/pixel/2020-07-01 advisory
- https://source.android.com/security/bulletin/2020-07-01 advisory
- https://www.qualcomm.com/company/product-security/bulletins/july-2020-bulletin url
- https://nvd.nist.gov/vuln/detail/CVE-2019-14123 advisory
- https://www.qualcomm.com/company/product-security/bulletins/july-2020-security-bulletin url