7.8
CVSSv3

CVE-2019-14040

Published: 07/02/2020 Updated: 10/02/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Using memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of unknown code in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX24, SM8150, SXR1130

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm apq8009_firmware -

qualcomm apq8017_firmware -

qualcomm apq8053_firmware -

qualcomm apq8096au_firmware -

qualcomm apq8098_firmware -

qualcomm mdm9150_firmware -

qualcomm mdm9206_firmware -

qualcomm mdm9207c_firmware -

qualcomm mdm9607_firmware -

qualcomm mdm9640_firmware -

qualcomm mdm9650_firmware -

qualcomm msm8905_firmware -

qualcomm msm8909w_firmware -

qualcomm msm8917_firmware -

qualcomm msm8920_firmware -

qualcomm msm8937_firmware -

qualcomm msm8940_firmware -

qualcomm msm8953_firmware -

qualcomm msm8996au_firmware -

qualcomm msm8998_firmware -

qualcomm qcs605_firmware -

qualcomm qm215_firmware -

qualcomm sda660_firmware -

qualcomm sda845_firmware -

qualcomm sdm429_firmware -

qualcomm sdm429w_firmware -

qualcomm sdm439_firmware -

qualcomm sdm450_firmware -

qualcomm sdm630_firmware -

qualcomm sdm632_firmware -

qualcomm sdm636_firmware -

qualcomm sdm660_firmware -

qualcomm sdm845_firmware -

qualcomm sdx20_firmware -

qualcomm sdx24_firmware -

qualcomm sm8150_firmware -

qualcomm sxr1130_firmware -

Github Repositories

PoC code for CVE-2019-14040

CVE-2019-14040 Proof-of-concept code for CVE-2019-14040 More details about the vulnerability are available in the blog post If you have any questions, you are welcome to DM me on Twitter (@tamir_zb) Build & Run In order to build, run Android NDK's ndk-build In order to run the PoC, run the binary using the following command: LD_PRELOAD=libQSEEComAPIso /qseecom