CVE-2019-10586: Buffer Overflow
Filling media attribute tag names without validating the destination buffer size which can result in the buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9205, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10586?
CVE-2019-10586 is classified as a high-severity vulnerability due to potential buffer overflow risks.
How do I fix CVE-2019-10586?
To mitigate CVE-2019-10586, users should ensure their devices have the latest firmware updates from Qualcomm or device manufacturers.
What vulnerabilities are associated with CVE-2019-10586?
CVE-2019-10586 can lead to untrusted memory access and potential exploitation by malicious applications.
Which devices are affected by CVE-2019-10586?
CVE-2019-10586 affects a broad range of Qualcomm chipsets used in devices such as Snapdragon Mobile, Snapdragon Compute, and more.
Is CVE-2019-10586 a remote code execution vulnerability?
Yes, CVE-2019-10586 allows for remote code execution through the exploitation of the buffer overflow.