← Vulnerability feed

Vulnerability record · CVE-2020-14127 · published 14 July 2022

CVE-2020-14127: Miui out-of-bounds write vulnerability

MMi · Miui

A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow and can be exploited by attackers to make remote denial of service.

7.5 CVSS 3.1 High EPSS 1.0% · top 37.9% CWE-787 · Out-of-bounds write
7.5CVSS 3.1 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by heap overflow and can be exploited by attackers to make remote denial of service.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-14127 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-14120Miui vulnerabilitySome Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party applic…EPSS 0.42%7.5CVE-2020-14125Miui out-of-bounds read vulnerabilityA denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited…EPSS 7.3%7.5CVE-2020-14123Miui double free vulnerabilityThere is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, …EPSS 0.93%5.5CVE-2020-14122Miui insufficient verification of data authenticity vulnerabilitySome Xiaomi phones have information leakage vulnerabilities, and some of them may be able to forge a specific identity due to the lack of parameter v…EPSS 0.16%5.5CVE-2020-14105Miui vulnerabilityThe application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.EPSS 0.26%5.5CVE-2020-14103Miui vulnerabilityThe application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.EPSS 0.70%5.5CVE-2020-14106Miui incorrect authorization vulnerabilityThe application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.…EPSS 0.66%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed

Source: NIST National Vulnerability Database (record CVE-2020-14127), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.