7.2
CVSSv2

CVE-2019-10537

Published: 18/12/2019 Updated: 23/12/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Improper validation of event buffer extracted from FW response can lead to integer overflow, which will allow to pass the length check and eventually will lead to buffer overwrite when event data is copied to context buffer in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, QCA6574AU, QCN7605, QCS405, QCS605, SDM660, SDM845, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm mdm9607_firmware -

qualcomm nicobar_firmware -

qualcomm qca6574au_firmware -

qualcomm qcn7605_firmware -

qualcomm qcs405_firmware -

qualcomm qcs605_firmware -

qualcomm sdm660_firmware -

qualcomm sdm845_firmware -

qualcomm sdx55_firmware -

qualcomm sm6150_firmware -

qualcomm sm7150_firmware -

qualcomm sm8150_firmware -

qualcomm sm8250_firmware -

qualcomm sxr1130_firmware -

qualcomm sxr2130_firmware -