CVE-2019-10626

MEDIUM

Qualcomm Snapdragon Firmware - Memory Corruption via Unvalidated Payload Size

Title source: llm
STIX 2.1

Description

Payload size is not validated before reading memory that may cause issue of accessing invalid pointer or some garbage data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, IPQ4019, IPQ6018, IPQ8064, IPQ8074, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS405, QCS605, Rennell, Saipan, SC8180X, SDA660, SDA845, SDM429W, SDM439, SDM670, SDM710, SDX20, SDX24, SDX55, SM8150, SM8250, SXR1130, SXR2130

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 13.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-119 CWE-20
Status published
Products (34)
qualcomm/apq8009_firmware
qualcomm/apq8017_firmware
qualcomm/apq8053_firmware
qualcomm/apq8096au_firmware
qualcomm/apq8098_firmware
qualcomm/ipq4019_firmware
qualcomm/ipq6018_firmware
qualcomm/ipq8064_firmware
qualcomm/ipq8074_firmware
qualcomm/mdm9206_firmware
... and 24 more
Published Jun 22, 2020
Tracked Since Feb 18, 2026