Vulnerability Details CVE-2019-14123
Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HLOS client as non-trustable in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, SXR2130
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.5%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 4.6
Products affected by CVE-2019-14123
-
cpe:2.3:h:qualcomm:kamorta:-
-
cpe:2.3:h:qualcomm:qcs404:-
-
cpe:2.3:h:qualcomm:rennell:-
-
cpe:2.3:h:qualcomm:sc7180:-
-
cpe:2.3:h:qualcomm:sdx55:-
-
cpe:2.3:h:qualcomm:sm6150:-
-
cpe:2.3:h:qualcomm:sm7150:-
-
cpe:2.3:h:qualcomm:sm8250:-
-
cpe:2.3:h:qualcomm:sxr2130:-
-
cpe:2.3:o:qualcomm:kamorta_firmware:-
-
cpe:2.3:o:qualcomm:qcs404_firmware:-
-
cpe:2.3:o:qualcomm:rennell_firmware:-
-
cpe:2.3:o:qualcomm:sc7180_firmware:-
-
cpe:2.3:o:qualcomm:sdx55_firmware:-
-
cpe:2.3:o:qualcomm:sm6150_firmware:-
-
cpe:2.3:o:qualcomm:sm7150_firmware:-
-
cpe:2.3:o:qualcomm:sm8250_firmware:-
-
cpe:2.3:o:qualcomm:sxr2130_firmware:-