← Vulnerability feed

Vulnerability record · CVE-2020-11207 · published 12 November 2020

CVE-2020-11207: Qualcomm apq8052 firmware classic buffer overflow vulnerability

Qualcomm · Apq8052 Firmware

Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8052, APQ8056, APQ8076, APQ8096, APQ8096SG, APQ8098, MDM9655, MSM8952, MSM8956, MSM8976, MSM8976SG, MSM8996, MSM8996SG, MSM8998, QCM4290, QCM6125, QCS410, QCS4290, QCS610, QCS6125, QSM8250, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SC7180, SDA640, SDA660, SDA845, SDA855, SDM640, SDM660, SDM830, SDM845, SDM850, SDX50M, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM6350, SM7125, SM7150, SM7150P, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SXR2130, SXR2130P

7.8 CVSS 3.1 High EPSS 1.5% · top 27.2% CWE-120 · Classic buffer overflow
7.8CVSS 3.1 base score, v2 7.2
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
62Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Buffer overflow in LibFastCV library due to improper size checks with respect to buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in APQ8052, APQ8056, APQ8076, APQ8096, APQ8096SG, APQ8098, MDM9655, MSM8952, MSM8956, MSM8976, MSM8976SG, MSM8996, MSM8996SG, MSM8998, QCM4290, QCM6125, QCS410, QCS4290, QCS610, QCS6125, QSM8250, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SC7180, SDA640, SDA660, SDA845, SDA855, SDM640, SDM660, SDM830, SDM845, SDM850, SDX50M, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM6350, SM7125, SM7150, SM7150P, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SXR2130, SXR2130P

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

62 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11207 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-21385Qualcomm chipset firmware memory corruption via alignment integer overflowA memory corruption flaw in Qualcomm chipset firmware arises from an integer overflow when alignments are used for memory allocation (CWE-190). It af…KEVEPSS 1.3%analysed9.8CVE-2022-40510Qualcomm apq8009 firmware out-of-bounds write vulnerabilityMemory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.EPSS 0.43%9.8CVE-2022-40515Qualcomm apq8009 firmware double free vulnerabilityMemory corruption in Video due to double free while playing 3gp clip with invalid metadata atoms.EPSS 0.33%9.8CVE-2022-25687Qualcomm apq8009 firmware classic buffer overflow vulnerabilitymemory corruption in video due to buffer overflow while parsing asf clips in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon…EPSS 0.35%9.8CVE-2022-25718Qualcomm apq8009 firmware unchecked return value vulnerabilityCryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Snapdragon Connectivity, Snapdra…EPSS 0.45%9.8CVE-2022-25720Qualcomm apq8009 firmware vulnerabilityMemory corruption in WLAN due to out of bound array access during connect/roaming in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn…EPSS 0.46%9.8CVE-2022-25748Qualcomm apq8009 firmware integer overflow vulnerabilityMemory corruption in WLAN due to integer overflow to buffer overflow while parsing GTK frames. in Snapdragon Auto, Snapdragon Compute, Snapdragon Con…EPSS 0.48%9.8CVE-2021-1972Qualcomm apq8009 firmware classic buffer overflow vulnerabilityPossible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity…EPSS 0.81%

Source: NIST National Vulnerability Database (record CVE-2020-11207), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.