CVE-2019-14093: Out-of-bounds Read
Array out of bound access can occur in display module due to lack of bound check on input parcel received in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MDM9650, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, QCM2150, QCS405, QCS605, QM215, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM632, SDM636, SDM660, SDX20
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-14093.
What is the severity of CVE-2019-14093?
The severity of CVE-2019-14093 is high with a severity value of 7.8.
Which software is affected by CVE-2019-14093?
CVE-2019-14093 affects Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, and Snapdragon Wearables in various models.
How does CVE-2019-14093 occur?
CVE-2019-14093 occurs due to lack of bound check on input parcel received in Snapdragon devices.
Are there any references for CVE-2019-14093?
Yes, there are references available for CVE-2019-14093. You can find them at the following links: - [Qualcomm July 2020 Bulletin](https://www.qualcomm.com/company/product-security/bulletins/july-2020-bulletin) - [Qualcomm July 2020 Security Bulletin](https://www.qualcomm.com/company/product-security/bulletins/july-2020-security-bulletin)