CVE-2019-10535
MEDIUMQualcomm Firmware - Memory Corruption in WLAN Loop Validation
Title source: llmDescription
Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iterating through loop in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8053, APQ8096AU, APQ8098, MDM9640, MSM8996AU, MSM8998, QCA6574AU, QCN7605, QCS405, QCS605, SDA845, SDM845, SDX20
References (1)
Core 1
Core References
Patch, Vendor Advisory x_refsource_confirm
https://www.qualcomm.com/company/product-security/bulletins/october-2019-bulletin
Scores
CVSS v3
5.5
EPSS
0.0004
EPSS Percentile
13.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-119
CWE-20
Status
published
Products (13)
qualcomm/apq8053_firmware
qualcomm/apq8096au_firmware
qualcomm/apq8098_firmware
qualcomm/mdm9640_firmware
qualcomm/msm8996au_firmware
qualcomm/msm8998_firmware
qualcomm/qca6574au_firmware
qualcomm/qcn7605_firmware
qualcomm/qcs405_firmware
qualcomm/qcs605_firmware
... and 3 more
Published
Nov 21, 2019
Tracked Since
Feb 18, 2026