Vulnerability Description
Possible buffer overflow when byte array receives incorrect input from reading source as array is not null terminated in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Nicobar, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR2130
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Nicobar Firmware | - |
| Qualcomm | Nicobar | - |
| Qualcomm | Sdm670 Firmware | - |
| Qualcomm | Sdm670 | - |
| Qualcomm | Sdm710 Firmware | - |
| Qualcomm | Sdm710 | - |
| Qualcomm | Sdm845 Firmware | - |
| Qualcomm | Sdm845 | - |
| Qualcomm | Sm6150 Firmware | - |
| Qualcomm | Sm6150 | - |
| Qualcomm | Sm8150 Firmware | - |
| Qualcomm | Sm8150 | - |
| Qualcomm | Sm8250 Firmware | - |
| Qualcomm | Sm8250 | - |
| Qualcomm | Sxr2130 Firmware | - |
| Qualcomm | Sxr2130 | - |
Related Weaknesses (CWE)
References
- https://www.qualcomm.com/company/product-security/bulletins/january-2020-bulletiVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletins/january-2020-bulletiVendor Advisory
FAQ
What is CVE-2019-14014?
CVE-2019-14014 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Possible buffer overflow when byte array receives incorrect input from reading source as array is not null terminated in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in Nicoba...
How severe is CVE-2019-14014?
CVE-2019-14014 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-14014?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Nicobar Firmware, Qualcomm Nicobar, Qualcomm Sdm670 Firmware, Qualcomm Sdm670, Qualcomm Sdm710 Firmware.