Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-2336


Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, SDX55, SM6150, SM7150, SM8150, SXR2130


Published

2019-11-21T15:15:16.463

Last Modified

2024-11-21T04:40:44.577

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-416
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System qualcomm mdm9205_firmware - Yes
Hardware qualcomm mdm9205 - No
Operating System qualcomm qcs404_firmware - Yes
Hardware qualcomm qcs404 - No
Operating System qualcomm sdx55_firmware - Yes
Hardware qualcomm sdx55 - No
Operating System qualcomm sm6150_firmware - Yes
Hardware qualcomm sm6150 - No
Operating System qualcomm sm7150_firmware - Yes
Hardware qualcomm sm7150 - No
Operating System qualcomm sm8150_firmware - Yes
Hardware qualcomm sm8150 - No
Operating System qualcomm sxr2130_firmware - Yes
Hardware qualcomm sxr2130 - No

References