10

CVE-2020-11184

u'Possible buffer overflow will occur in video while parsing mp4 clip with crafted esds atom size.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile in QCM4290, QCS4290, QM215, QSM8350, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6250, SM6350, SM7125, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QualcommQcm4290 Firmware Version-
   QualcommQcm4290 Version-
QualcommQcs4290 Firmware Version-
   QualcommQcs4290 Version-
QualcommQm215 Firmware Version-
   QualcommQm215 Version-
QualcommQsm8350 Firmware Version-
   QualcommQsm8350 Version-
QualcommSa6145p Firmware Version-
   QualcommSa6145p Version-
QualcommSa6155 Firmware Version-
   QualcommSa6155 Version-
QualcommSa6155p Firmware Version-
   QualcommSa6155p Version-
QualcommSa8155 Firmware Version-
   QualcommSa8155 Version-
QualcommSa8155p Firmware Version-
   QualcommSa8155p Version-
QualcommSdx55 Firmware Version-
   QualcommSdx55 Version-
QualcommSdx55m Firmware Version-
   QualcommSdx55m Version-
QualcommSm4250 Firmware Version-
   QualcommSm4250 Version-
QualcommSm4250p Firmware Version-
   QualcommSm4250p Version-
QualcommSm6115 Firmware Version-
   QualcommSm6115 Version-
QualcommSm6115p Firmware Version-
   QualcommSm6115p Version-
QualcommSm6125 Firmware Version-
   QualcommSm6125 Version-
QualcommSm6250 Firmware Version-
   QualcommSm6250 Version-
QualcommSm6350 Firmware Version-
   QualcommSm6350 Version-
QualcommSm7125 Firmware Version-
   QualcommSm7125 Version-
QualcommSm7225 Firmware Version-
   QualcommSm7225 Version-
QualcommSm7250 Firmware Version-
   QualcommSm7250 Version-
QualcommSm7250p Firmware Version-
   QualcommSm7250p Version-
QualcommSm8150 Firmware Version-
   QualcommSm8150 Version-
QualcommSm8150p Firmware Version-
   QualcommSm8150p Version-
QualcommSm8250 Firmware Version-
   QualcommSm8250 Version-
QualcommSm8350 Firmware Version-
   QualcommSm8350 Version-
QualcommSm8350p Firmware Version-
   QualcommSm8350p Version-
QualcommSxr2130 Firmware Version-
   QualcommSxr2130 Version-
QualcommSxr2130p Firmware Version-
   QualcommSxr2130p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.594
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-190 Integer Overflow or Wraparound

The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.