CVE-2020-0128
Last modified
CVE-2020-0128 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges required. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123940919
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 10.0 |
References
- https://source.android.com/security/bulletin/pixel/2020-06-01Patch, Vendor Advisory
- https://source.android.com/security/bulletin/pixel/2020-06-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-0128?
How severe is CVE-2020-0128?
How do I fix CVE-2020-0128?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-0122In the permission declaration for com.google.android.provide…6.7
- CVE-2020-0123There is a possible out of bounds write due to an incorrect …9.8
- CVE-2020-0124In markBootComplete of InstalldNativeService.cpp, there is a…6.7
- CVE-2020-0125In mediadrm, there is a possible out of bounds read due to a…5.5
- CVE-2020-0126In multiple functions in DrmPlugin.cpp, there is a possible …6.4
- CVE-2020-0127In AudioStream::decode of AudioGroup.cpp, there is a possibl…6.5
- CVE-2020-0129In SetData of btm_ble_multi_adv.cc, there is a possible out-…7.8
- CVE-2020-0130In screencap, there is a possible command injection due to i…7.8
- CVE-2020-0131In parseChunk of MPEG4Extractor.cpp, there is a possible out…8.8
- CVE-2020-0132In BnAAudioService::onTransact of IAAudioService.cpp, there …5.5
- CVE-2020-0133In MockLocationAppPreferenceController.java, it is possible …7.3
- CVE-2020-0134In BnDrm::onTransact of IDrm.cpp, there is a possible inform…5.5
Are you affected by CVE-2020-0128?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
