CVE-2019-2304 PUBLISHED CVSS 7.800000190734863 HIGH

Integer overflow to buffer overflow due to lack of validation of event arguments received from firmware. in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8917, MSM8920, MSM8937, MSM8940, QCN7605, QCS405, QCS605, SDA845, SDM660, SDM845, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130

EPSS 0.03% · 10.1th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.03%
10.1th percentile

Affected Products

VendorProductVersions
qualcommqcn7605_firmware
qualcommsm7150_firmware
qualcommsdm660_firmware
qualcommsxr1130_firmware
qualcommsdx24_firmware
qualcommmsm8917_firmware
qualcommmsm8940_firmware
qualcommsdm845_firmware
qualcommmdm9607_firmware
qualcommsda845_firmware
Qualcomm, Inc.Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and NetworkingIPQ4019, IPQ8064, IPQ8074, MDM9607, MSM8917, MSM8920, MSM8937, MSM8940, QCN7605, QCS405, QCS605, SDA845, SDM660, SDM845, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130
qualcommmsm8937_firmware
qualcommsdx55_firmware
qualcommqcs405_firmware
qualcommsm8150_firmware
qualcommqcs605_firmware
qualcommipq8064_firmware
qualcommsm6150_firmware
qualcommipq8074_firmware
qualcommmsm8920_firmware

…and 1 more

Timeline

References

Open in Interactive Console →