CVE-2019-14004: Input Validation
Buffer overflow occurs while processing invalid MKV clip, which has invalid EBML size in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS605, QM215, Rennell, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14004?
CVE-2019-14004 has been rated as a critical vulnerability due to the potential for remote code execution from a buffer overflow.
How do I fix CVE-2019-14004?
To fix CVE-2019-14004, it is recommended to update the affected Qualcomm firmware provided by Qualcomm or the specific device manufacturer.
Which devices are affected by CVE-2019-14004?
CVE-2019-14004 affects various Qualcomm Snapdragon processors and platforms, including those used in Android devices.
What type of vulnerability is CVE-2019-14004?
CVE-2019-14004 is a buffer overflow vulnerability that occurs during processing invalid MKV clips.
Are there any known exploits for CVE-2019-14004?
Currently, there are no publicly known exploits explicitly targeting CVE-2019-14004, but the risk is notable due to the vulnerability's nature.