ZeroHour

CVE-2019-2293

CVSS 3.0
7.8 high
EPSS
<1%p10
Published
()
Modified
Description

Pointer dereference while freeing IFE resources due to lack of length check of in port resource. in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, QCS405, QCS605, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24

Vendors
qualcomm
Products
msm8909w firmware, qcs405 firmware, qcs605 firmware, sd 425 firmware, sd 427 firmware, sd 430 firmware, sd 435 firmware, sd 450 firmware, sd 625 firmware, sd 636 firmware, sd 675 firmware, sd 712 firmware
Weakness
CWE-416
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.