ZeroHour

CVE-2020-3676

CVSS 3.1
7.8 high
EPSS
<1%p10
Published
()
Modified
Description

Possible memory corruption in perfservice due to improper validation array length taken from user application. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8096AU, APQ8098, Kamorta, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, Saipan, SDM429, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

Vendors
qualcomm
Products
apq8096au firmware, apq8098 firmware, kamorta firmware, msm8917 firmware, msm8920 firmware, msm8937 firmware, msm8940 firmware, msm8953 firmware, msm8998 firmware, nicobar firmware, qcm2150 firmware, qcs605 firmware
Weakness
CWE-20, CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.