CVE-2019-14056

HIGH

Qualcomm Kamorta and Related Firmware - Integer Overflow in Cert Extension OID Range Count

Title source: llm
STIX 2.1

Description

u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, MDM9150, MDM9205, MDM9607, MDM9650, Nicobar, QCS404, QCS405, QCS605, QCS610, Rennell, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130

Scores

CVSS v3 7.8
EPSS 0.0003
EPSS Percentile 9.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (29)
qualcomm/kamorta_firmware
qualcomm/mdm9150_firmware
qualcomm/mdm9205_firmware
qualcomm/mdm9607_firmware
qualcomm/mdm9650_firmware
qualcomm/nicobar_firmware
qualcomm/qcs404_firmware
qualcomm/qcs405_firmware
qualcomm/qcs605_firmware
qualcomm/qcs610_firmware
... and 19 more
Published Sep 08, 2020
Tracked Since Feb 18, 2026