7.8
CVSSv3

CVE-2019-10624

Published: 16/04/2020 Updated: 21/07/2021
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

While handling the vendor command there is an integer truncation issue that could yield a buffer overflow due to int data type copied to u8 data type in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, MSM8996AU, QCA6574AU, QCN7605, Rennell, SC8180X, SDM710, SDX55, SM7150, SM8150, SM8250, SXR2130

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm apq8096au_firmware -

qualcomm msm8996au_firmware -

qualcomm qca6574au_firmware -

qualcomm qcn7605_firmware -

qualcomm rennell_firmware -

qualcomm sc8180x_firmware -

qualcomm sdm710_firmware -

qualcomm sdx55_firmware -

qualcomm sm7150_firmware -

qualcomm sm8150_firmware -

qualcomm sm8250_firmware -

qualcomm sxr2130_firmware -