9.8

CVE-2020-3662

Buffer overflow can occur while parsing eac3 header while playing the clip which is nonstandard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, MSM8909W, MSM8917, MSM8953, MSM8996, MSM8996AU, MSM8998, QCA6574AU, QCS405, QCS605, QM215, Rennell, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR2130

Data is provided by the National Vulnerability Database (NVD)
QualcommApq8009 Firmware Version-
   QualcommApq8009 Version-
QualcommApq8017 Firmware Version-
   QualcommApq8017 Version-
QualcommApq8053 Firmware Version-
   QualcommApq8053 Version-
QualcommApq8096au Firmware Version-
   QualcommApq8096au Version-
QualcommApq8098 Firmware Version-
   QualcommApq8098 Version-
QualcommMsm8909w Firmware Version-
   QualcommMsm8909w Version-
QualcommMsm8917 Firmware Version-
   QualcommMsm8917 Version-
QualcommMsm8953 Firmware Version-
   QualcommMsm8953 Version-
QualcommMsm8996 Firmware Version-
   QualcommMsm8996 Version-
QualcommMsm8996au Firmware Version-
   QualcommMsm8996au Version-
QualcommMsm8998 Firmware Version-
   QualcommMsm8998 Version-
QualcommQca6574au Firmware Version-
   QualcommQca6574au Version-
QualcommQcs405 Firmware Version-
   QualcommQcs405 Version-
QualcommQcs605 Firmware Version-
   QualcommQcs605 Version-
QualcommQm215 Firmware Version-
   QualcommQm215 Version-
QualcommRennell Firmware Version-
   QualcommRennell Version-
QualcommSaipan Firmware Version-
   QualcommSaipan Version-
QualcommSda660 Firmware Version-
   QualcommSda660 Version-
QualcommSdm429 Firmware Version-
   QualcommSdm429 Version-
QualcommSdm429w Firmware Version-
   QualcommSdm429w Version-
QualcommSdm439 Firmware Version-
   QualcommSdm439 Version-
QualcommSdm450 Firmware Version-
   QualcommSdm450 Version-
QualcommSdm630 Firmware Version-
   QualcommSdm630 Version-
QualcommSdm632 Firmware Version-
   QualcommSdm632 Version-
QualcommSdm636 Firmware Version-
   QualcommSdm636 Version-
QualcommSdm660 Firmware Version-
   QualcommSdm660 Version-
QualcommSdm845 Firmware Version-
   QualcommSdm845 Version-
QualcommSdx20 Firmware Version-
   QualcommSdx20 Version-
QualcommSm6150 Firmware Version-
   QualcommSm6150 Version-
QualcommSm7150 Firmware Version-
   QualcommSm7150 Version-
QualcommSm8150 Firmware Version-
   QualcommSm8150 Version-
QualcommSm8250 Firmware Version-
   QualcommSm8250 Version-
QualcommSxr2130 Firmware Version-
   QualcommSxr2130 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.36% 0.548
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.