Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-14046


Out of bound access while allocating memory for an array in camera due to improper validation of elements parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS605, SDM439, SDX24


Published

2020-02-07T05:15:11.777

Last Modified

2024-11-21T04:25:58.533

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-129

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm qcs605_firmware - Yes
Hardware qualcomm qcs605 - No
Operating System qualcomm sdm439_firmware - Yes
Hardware qualcomm sdm439 - No
Operating System qualcomm sdx24_firmware - Yes
Hardware qualcomm sdx24 - No

References