ZeroHour

CVE-2019-14123

CVSS 3.1
7.8 high
EPSS
<1%p10
Published
()
Modified
Description

Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HLOS client as non-trustable in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130

Vendors
qualcomm
Products
kamorta firmware, qcs404 firmware, rennell firmware, sc7180 firmware, sdx55 firmware, sm6150 firmware, sm7150 firmware, sm8250 firmware, sxr2130 firmware
Weakness
CWE-20, CWE-125, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.