TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2019-10537

HIGH
7.8

Beschreibung

Improper validation of event buffer extracted from FW response can lead to integer overflow, which will allow to pass the length check and eventually will lead to buffer overwrite when event data is copied to context buffer in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, QCA6574AU, QCN7605, QCS405, QCS605, SDM660, SDM845, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

CVE Details

CVSS v3.1 Bewertung7.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorLOCAL
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht12/18/2019
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

qualcomm:mdm9607qualcomm:mdm9607_firmwarequalcomm:nicobarqualcomm:nicobar_firmwarequalcomm:qca6574auqualcomm:qca6574au_firmwarequalcomm:qcn7605qualcomm:qcn7605_firmwarequalcomm:qcs405qualcomm:qcs405_firmwarequalcomm:qcs605qualcomm:qcs605_firmwarequalcomm:sdm660qualcomm:sdm660_firmwarequalcomm:sdm845qualcomm:sdm845_firmwarequalcomm:sdx55qualcomm:sdx55_firmwarequalcomm:sm6150qualcomm:sm6150_firmwarequalcomm:sm7150qualcomm:sm7150_firmwarequalcomm:sm8150qualcomm:sm8150_firmwarequalcomm:sm8250qualcomm:sm8250_firmwarequalcomm:sxr1130qualcomm:sxr1130_firmwarequalcomm:sxr2130qualcomm:sxr2130_firmware

Schwachen (CWE)

CWE-190

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.