CVE-2019-14104
Summary
| CVE | CVE-2019-14104 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-16 11:15:00 UTC |
| Updated | 2020-04-21 20:25:00 UTC |
| Description | Slab-out-of-bounds access can occur if the context pointer is invalid due to lack of null check on pointer before accessing it in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Mobile in APQ8053, SC8180X, SDX55, SM8150 |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qualcomm | Apq8053 | - | All | All | All |
| Hardware | Qualcomm | Apq8053 | - | All | All | All |
| Operating System | Qualcomm | Apq8053 Firmware | - | All | All | All |
| Operating System | Qualcomm | Apq8053 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sc8180x | - | All | All | All |
| Hardware | Qualcomm | Sc8180x | - | All | All | All |
| Operating System | Qualcomm | Sc8180x Firmware | - | All | All | All |
| Operating System | Qualcomm | Sc8180x Firmware | - | All | All | All |
| Hardware | Qualcomm | Sdx55 | - | All | All | All |
| Hardware | Qualcomm | Sdx55 | - | All | All | All |
| Operating System | Qualcomm | Sdx55 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sdx55 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sm8150 | - | All | All | All |
| Hardware | Qualcomm | Sm8150 | - | All | All | All |
| Operating System | Qualcomm | Sm8150 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sm8150 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| April 2020 Bulletin | Qualcomm | CONFIRM | www.qualcomm.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.