9.8

CVE-2024-20011

In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441146; Issue ID: ALPS08441146.

Data is provided by the National Vulnerability Database (NVD)
GoogleAndroid Version11.0
   MediatekMt6985 Version-
   MediatekMt8127 Version-
   MediatekMt8135 Version-
   MediatekMt8167 Version-
   MediatekMt8167s Version-
   MediatekMt8168 Version-
   MediatekMt8173 Version-
   MediatekMt8175 Version-
   MediatekMt8176 Version-
   MediatekMt8183 Version-
   MediatekMt8185 Version-
   MediatekMt8188 Version-
   MediatekMt8188t Version-
   MediatekMt8195 Version-
   MediatekMt8195z Version-
   MediatekMt8312c Version-
   MediatekMt8312d Version-
GoogleAndroid Version12.0
   MediatekMt6985 Version-
   MediatekMt8127 Version-
   MediatekMt8135 Version-
   MediatekMt8167 Version-
   MediatekMt8167s Version-
   MediatekMt8168 Version-
   MediatekMt8173 Version-
   MediatekMt8175 Version-
   MediatekMt8176 Version-
   MediatekMt8183 Version-
   MediatekMt8185 Version-
   MediatekMt8188 Version-
   MediatekMt8188t Version-
   MediatekMt8195 Version-
   MediatekMt8195z Version-
   MediatekMt8312c Version-
   MediatekMt8312d Version-
GoogleAndroid Version13.0
   MediatekMt6985 Version-
   MediatekMt8127 Version-
   MediatekMt8135 Version-
   MediatekMt8167 Version-
   MediatekMt8167s Version-
   MediatekMt8168 Version-
   MediatekMt8173 Version-
   MediatekMt8175 Version-
   MediatekMt8176 Version-
   MediatekMt8183 Version-
   MediatekMt8185 Version-
   MediatekMt8188 Version-
   MediatekMt8188t Version-
   MediatekMt8195 Version-
   MediatekMt8195z Version-
   MediatekMt8312c Version-
   MediatekMt8312d Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.27% 0.867
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.