VDB

CVE-2020-3641

CVE-2020-3641 PUBLISHED CVSS 9.800000190734863 CRITICAL

Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8053, APQ8096AU, APQ8098, Kamorta, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8953, MSM8996AU, MSM8998, QCA6574AU, QCM2150, QCS405, QCS605, QM215, Rennell, SA6155P, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR2130

EPSS 0.31% · 54.6th percentile

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.31%
54.6th percentile

Affected Products

VendorProductVersions
qualcommmdm9206_firmware
qualcommsdm450_firmware
qualcommmdm9607_firmware
qualcommsdm632_firmware
qualcommapq8009_firmware
qualcommkamorta_firmware
qualcommmsm8909w_firmware
qualcommsa6155p_firmware
qualcommqcs605_firmware
qualcommsdm429w_firmware
qualcommsdm429_firmware
qualcommapq8053_firmware
qualcommmsm8998_firmware
qualcommsdm845_firmware
qualcommqca6574au_firmware
qualcommapq8098_firmware
qualcommqcm2150_firmware
qualcommmdm9207c_firmware
qualcommsdm439_firmware
qualcommsdm660_firmware

…and 19 more

Timeline

  • May 5, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 27, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 2, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›