CVE-2019-10541
CRITICALQualcomm Snapdragon Firmware - Use-After-Free via FLV Clip Parsing
Title source: llmDescription
Dereference on uninitialized buffer can happen when parsing FLV clip with corrupted codec specific data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607, MSM8909W, MSM8996AU, QCA6574AU, QCS405, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 600, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://source.android.com/security/bulletin/
Scores
CVSS v3
9.8
EPSS
0.0030
EPSS Percentile
53.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
CWE-908
Status
published
Products (36)
qualcomm/mdm9206_firmware
qualcomm/mdm9607_firmware
qualcomm/msm8909w_firmware
qualcomm/msm8996au_firmware
qualcomm/qca6574au_firmware
qualcomm/qcs405_firmware
qualcomm/qcs605_firmware
qualcomm/qualcomm_215_firmware
qualcomm/sd_205_firmware
qualcomm/sd_210_firmware
... and 26 more
Published
Nov 06, 2019
Tracked Since
Feb 18, 2026