CVE-2019-2339 PUBLISHED CVSS 7.800000190734863 HIGH

Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130

EPSS 0.09% · 26.3th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.09%
26.3th percentile

Affected Products

VendorProductVersions
qualcommsdm850_firmware
qualcommsm8150_firmware
qualcommsdx24_firmware
qualcommqcs605_firmware
qualcommsdm710_firmware
qualcommsm6150_firmware
qualcommsxr1130_firmware
qualcommsdm845_firmware
qualcommsdx55_firmware
Qualcomm, Inc.Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and NetworkingMDM9205, QCS404, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130
qualcommqcs404_firmware
qualcommsdm670_firmware
qualcommsda845_firmware
qualcommmdm9205_firmware
qualcommsm7150_firmware
qualcommsxr2130_firmware

Timeline

References

Open in Interactive Console →