CVE-2020-3688 PUBLISHED CVSS 9.800000190734863 CRITICAL

Possible buffer overflow while parsing mp4 clip with corrupted sample atoms due to improper validation of index in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Kamorta, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA6574AU, QCM2150, QCS405, QCS605, QM215, Rennell, SA6155P, Saipan, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

EPSS 0.40% · 60.8th percentile

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.40%
60.8th percentile

Affected Products

VendorProductVersions
qualcommmsm8905_firmware
qualcommmsm8953_firmware
qualcommsdm660_firmware
qualcommsm6150_firmware
qualcommsdm630_firmware
qualcommmsm8940_firmware
qualcommsdm429_firmware
qualcommsda845_firmware
qualcommsdm670_firmware
qualcommsm8250_firmware
qualcommsdm429w_firmware
qualcommapq8096au_firmware
qualcommqcm2150_firmware
qualcommsdm710_firmware
qualcommrennell_firmware
qualcommkamorta_firmware
qualcommsm7150_firmware
qualcommqm215_firmware
qualcommsda660_firmware
qualcommqcs405_firmware

…and 29 more

Timeline

References

Open in Interactive Console →