ZeroHour

CVE-2019-14042

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
Description

Out of bound read in in fingerprint application due to requested data assigned to a local buffer without length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, MDM9205, Nicobar, QCS404, QCS405, QCS605, Rennell, SA415M, SA6155P, SC7180, SC8180X, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

Vendors
qualcomm
Products
kamorta firmware, mdm9205 firmware, nicobar firmware, qcs404 firmware, qcs405 firmware, qcs605 firmware, rennell firmware, sa415m firmware, sa6155p firmware, sc7180 firmware, sc8180x firmware, sdm670 firmware
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.