CVE-2019-14123

HIGH

Widevine HLOS Client - Buffer Overflow

Title source: llm
STIX 2.1

Description

Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HLOS client as non-trustable in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 16.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-125 CWE-20 CWE-787
Status published
Products (9)
qualcomm/kamorta_firmware
qualcomm/qcs404_firmware
qualcomm/rennell_firmware
qualcomm/sc7180_firmware
qualcomm/sdx55_firmware
qualcomm/sm6150_firmware
qualcomm/sm7150_firmware
qualcomm/sm8250_firmware
qualcomm/sxr2130_firmware
Published Jul 30, 2020
Tracked Since Feb 18, 2026