CVE-2019-14040: Use After Free
Using memory after being freed in qsee due to wrong implementation can lead to unexpected behavior such as execution of unknown code in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SDX24, SM8150, SXR1130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14040?
CVE-2019-14040 has been rated as a high-severity vulnerability due to its potential to allow execution of arbitrary code.
How do I fix CVE-2019-14040?
To address CVE-2019-14040, ensure you apply the latest firmware updates provided by Qualcomm for the affected devices.
What systems are affected by CVE-2019-14040?
CVE-2019-14040 affects various Qualcomm Snapdragon technologies across devices such as automotive, IoT, and mobile platforms.
What causes CVE-2019-14040?
CVE-2019-14040 is caused by improper memory management that results in the use of memory after it has been freed.
Can CVE-2019-14040 be exploited remotely?
Yes, CVE-2019-14040 can potentially be exploited remotely, leading to unauthorized code execution on vulnerable devices.