← Vulnerability feed

Vulnerability record · CVE-2020-11268 · published 7 May 2021

CVE-2020-11268: Qualcomm apq8009 improper input validation vulnerability

Qualcomm · Apq8009

Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of service in Snapdragon Auto, Snapdragon Mobile

7.5 CVSS 3.1 High EPSS 0.67% · top 49.6% CWE-20 · Improper input validation
7.5CVSS 3.1 base score, v2 5.0
0.67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
86Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Potential UE reset while decoding a crafted Sib1 or SIB1 that schedules unsupported SIBs and can lead to denial of service in Snapdragon Auto, Snapdragon Mobile

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

86 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-11268 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-11283Qualcomm apq8009 out-of-bounds write vulnerabilityA buffer overflow can occur when playing an MKV clip due to lack of input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity,…EPSS 0.71%9.8CVE-2020-3691Qualcomm apq8009 vulnerabilityPossible out of bound memory access in audio due to integer underflow while processing modified contents in Snapdragon Auto, Snapdragon Compute, Snap…EPSS 1.1%9.8CVE-2020-3686Qualcomm apq8009 classic buffer overflow vulnerabilityPossible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of arr…EPSS 1.2%9.8CVE-2020-11213Qualcomm apq8009 out-of-bounds read vulnerabilityOut of bound reads might occur in while processing Service descriptor due to improper validation of length of fields in Snapdragon Auto, Snapdragon C…EPSS 0.87%9.8CVE-2020-11197Qualcomm apq8009 integer overflow vulnerabilityPossible integer overflow can occur when stream info update is called when total number of streams detected are zero while parsing TS clip with inval…EPSS 0.91%9.8CVE-2020-11216Qualcomm apq8009 out-of-bounds read vulnerabilityBuffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, Snapdragon Compute, Snapdrago…EPSS 0.91%9.8CVE-2020-11212Qualcomm apq8009 out-of-bounds read vulnerabilityOut of bounds reads while parsing NAN beacons attributes and OUIs due to improper length of field check in Snapdragon Auto, Snapdragon Compute, Snapd…EPSS 0.87%9.8CVE-2020-11143Qualcomm apq8009 out-of-bounds write vulnerabilityOut of bound memory access during music playback with modified content due to copying data without checking destination buffer size in Snapdragon Aut…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2020-11268), CISA KEV, FIRST EPSS (scores of 2026-10-04). This page is refreshed as NVD updates the record.