CVE-2020-11140

CRITICAL

Qualcomm APQ8017 and related - Out-of-bounds Write during ALAC Music Playback

Title source: llm
STIX 2.1

Description

Out of bound memory access during music playback with ALAC modified content due to improper validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

Scores

CVSS v3 9.8
EPSS 0.0033
EPSS Percentile 56.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (50)
qualcomm/apq8017
qualcomm/apq8037
qualcomm/apq8052
qualcomm/apq8053
qualcomm/apq8056
qualcomm/apq8062
qualcomm/apq8064au
qualcomm/apq8076
qualcomm/apq8084
qualcomm/apq8096au
... and 40 more
Published Jan 21, 2021
Tracked Since Feb 18, 2026