7.8

CVE-2019-2312

When handling the vendor command there exists a potential buffer overflow due to lack of input validation of data buffer received in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, MDM9640, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommMdm9607 Firmware Version-
   QualcommMdm9607 Version-
QualcommMdm9640 Firmware Version-
   QualcommMdm9640 Version-
QualcommMsm8996au Firmware Version-
   QualcommMsm8996au Version-
QualcommQca6174a Firmware Version-
   QualcommQca6174a Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQca9377 Firmware Version-
   QualcommQca9377 Version-
QualcommQca9379 Firmware Version-
   QualcommQca9379 Version-
QualcommQcs405 Firmware Version-
   QualcommQcs405 Version-
QualcommQcs605 Firmware Version-
   QualcommQcs605 Version-
QualcommSd 210 Firmware Version-
   QualcommSd 210 Version-
QualcommSd 212 Firmware Version-
   QualcommSd 212 Version-
QualcommSd 205 Firmware Version-
   QualcommSd 205 Version-
QualcommSd 425 Firmware Version-
   QualcommSd 425 Version-
QualcommSd 427 Firmware Version-
   QualcommSd 427 Version-
QualcommSd 430 Firmware Version-
   QualcommSd 430 Version-
QualcommSd 435 Firmware Version-
   QualcommSd 435 Version-
QualcommSd 450 Firmware Version-
   QualcommSd 450 Version-
QualcommSd 600 Firmware Version-
   QualcommSd 600 Version-
QualcommSd 625 Firmware Version-
   QualcommSd 625 Version-
QualcommSd 636 Firmware Version-
   QualcommSd 636 Version-
QualcommSd 665 Firmware Version-
   QualcommSd 665 Version-
QualcommSd 675 Firmware Version-
   QualcommSd 675 Version-
QualcommSd 712 Firmware Version-
   QualcommSd 712 Version-
QualcommSd 710 Firmware Version-
   QualcommSd 710 Version-
QualcommSd 670 Firmware Version-
   QualcommSd 670 Version-
QualcommSd 730 Firmware Version-
   QualcommSd 730 Version-
QualcommSd 820 Firmware Version-
   QualcommSd 820 Version-
QualcommSd 820a Firmware Version-
   QualcommSd 820a Version-
QualcommSd 835 Firmware Version-
   QualcommSd 835 Version-
QualcommSd 845 Firmware Version-
   QualcommSd 845 Version-
QualcommSd 850 Firmware Version-
   QualcommSd 850 Version-
QualcommSd 855 Firmware Version-
   QualcommSd 855 Version-
QualcommSdm630 Firmware Version-
   QualcommSdm630 Version-
QualcommSdm660 Firmware Version-
   QualcommSdm660 Version-
QualcommSdx24 Firmware Version-
   QualcommSdx24 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.105
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.