CVE-2020-11140
CRITICALQualcomm APQ8017 and related - Out-of-bounds Write during ALAC Music Playback
Title source: llmDescription
Out of bound memory access during music playback with ALAC modified content due to improper validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
References (2)
Core 2
Core References
Broken Link x_refsource_confirm
https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin
Scores
CVSS v3
9.8
EPSS
0.0033
EPSS Percentile
56.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (50)
qualcomm/apq8017
qualcomm/apq8037
qualcomm/apq8052
qualcomm/apq8053
qualcomm/apq8056
qualcomm/apq8062
qualcomm/apq8064au
qualcomm/apq8076
qualcomm/apq8084
qualcomm/apq8096au
... and 40 more
Published
Jan 21, 2021
Tracked Since
Feb 18, 2026