CVE-2019-14046

HIGH

Snapdragon Auto <QCS605 - Memory Corruption

Title source: llm
STIX 2.1

Description

Out of bound access while allocating memory for an array in camera due to improper validation of elements parameters in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in QCS605, SDM439, SDX24

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 10.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-129
Status published
Products (3)
qualcomm/qcs605_firmware
qualcomm/sdm439_firmware
qualcomm/sdx24_firmware
Published Feb 07, 2020
Tracked Since Feb 18, 2026