6.8

CVE-2020-11305

Integer overflow in boot due to improper length check on arguments received in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

Data is provided by the National Vulnerability Database (NVD)
QualcommApq8009 Firmware Version-
   QualcommApq8009 Version-
QualcommApq8053 Firmware Version-
   QualcommApq8053 Version-
QualcommMdm9206 Firmware Version-
   QualcommMdm9206 Version-
QualcommPm8909 Firmware Version-
   QualcommPm8909 Version-
QualcommPm8916 Firmware Version-
   QualcommPm8916 Version-
QualcommPm8953 Firmware Version-
   QualcommPm8953 Version-
QualcommPmd9607 Firmware Version-
   QualcommPmd9607 Version-
QualcommPmi8952 Firmware Version-
   QualcommPmi8952 Version-
QualcommQca9367 Firmware Version-
   QualcommQca9367 Version-
QualcommQca9377 Firmware Version-
   QualcommQca9377 Version-
QualcommSmb1358 Firmware Version-
   QualcommSmb1358 Version-
QualcommSmb1360 Firmware Version-
   QualcommSmb1360 Version-
QualcommSmb231 Firmware Version-
   QualcommSmb231 Version-
QualcommWcd9326 Firmware Version-
   QualcommWcd9326 Version-
QualcommWcd9330 Firmware Version-
   QualcommWcd9330 Version-
QualcommWcn3660b Firmware Version-
   QualcommWcn3660b Version-
QualcommWcn3680b Firmware Version-
   QualcommWcn3680b Version-
QualcommWsa8810 Firmware Version-
   QualcommWsa8810 Version-
QualcommWsa8815 Firmware Version-
   QualcommWsa8815 Version-
QualcommWtr2965 Firmware Version-
   QualcommWtr2965 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.106
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.