ZeroHour

CVE-2019-14088

CVSS 3.1
7.8 high
EPSS
<1%p21
Published
()
Modified
Description

Possible use after free issue while CRM is accessing the link pointer from device private data due to lack of resource protection in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, MDM9206, MDM9207C, MDM9607, QCS605, SDM429W, SDX24, SM8150, SXR1130

Vendors
qualcomm
Products
apq8009 firmware, mdm9206 firmware, mdm9207c firmware, mdm9607 firmware, qcs605 firmware, sdm429w firmware, sdx24 firmware, sm8150 firmware, sxr1130 firmware
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.