CVE-2019-10502

HIGH

Qualcomm Snapdragon Firmware - Stack Overflow in Camera Module

Title source: llm
STIX 2.1

Description

Possible stack overflow when an index equal to io buffer size is accessed in camera module in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MSM8909W, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 845 / SD 850, SD 855, SDM439, SDX24

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 17.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (24)
qualcomm/msm8909w_firmware
qualcomm/qcs405_firmware
qualcomm/qcs605_firmware
qualcomm/qualcomm_215_firmware
qualcomm/sd_205_firmware
qualcomm/sd_210_firmware
qualcomm/sd_212_firmware
qualcomm/sd_425_firmware
qualcomm/sd_429_firmware
qualcomm/sd_439_firmware
... and 14 more
Published Nov 06, 2019
Tracked Since Feb 18, 2026