CVE-2020-0336
Last modified
CVE-2020-0336 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153467444
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 11.0 |
References
- https://source.android.com/security/bulletin/android-11Vendor Advisory
- https://source.android.com/security/bulletin/android-11Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-0336?
How severe is CVE-2020-0336?
How do I fix CVE-2020-0336?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-0330In iorap, there is a possible memory corruption due to a use…6.7
- CVE-2020-0331In Settings, there is a possible permissions bypass. This co…5.5
- CVE-2020-0332In libstagefright, there is a possible dead loop due to an u…6.5
- CVE-2020-0333In UrlQuerySanitizer, there is a possible improper input val…9.8
- CVE-2020-0334In NFC, there is a possible out of bounds write due to a mis…6.7
- CVE-2020-0335In NFC, there is a possible out of bounds write due to a mis…6.7
- CVE-2020-0337In MediaProvider, there is a possible bypass of a permission…5.5
- CVE-2020-0338In checkKeyIntent of AccountManagerService.java, there is a …5
- CVE-2020-0339There is a possible out of bounds read due to a missing boun…9.1
- CVE-2020-0340In libcodec2_soft_mp3dec, there is a possible information di…6.5
- CVE-2020-0341In DisplayManager, there is a possible permission bypass due…7.8
- CVE-2020-0342There is a possible out of bounds write due to an incorrect …9.8
Are you affected by CVE-2020-0336?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
