CVE-2020-3632
Last modified
CVE-2020-3632 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. u'Incorrect validation of ring context fetched from host memory can lead to memory overflow' in Snapdragon Compute, Snapdragon Mobile in QSM8350, SC7180, SDX55, SDX55M, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
u'Incorrect validation of ring context fetched from host memory can lead to memory overflow' in Snapdragon Compute, Snapdragon Mobile in QSM8350, SC7180, SDX55, SDX55M, SM6150, SM6250, SM6250P, SM7125, SM7150, SM7150P, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Qsm8350 Firmware | All versions |
| Qualcomm | Sc7180 Firmware | All versions |
| Qualcomm | Sdx55 Firmware | All versions |
| Qualcomm | Sdx55m Firmware | All versions |
| Qualcomm | Sm6150 Firmware | All versions |
| Qualcomm | Sm6250 Firmware | All versions |
| Qualcomm | Sm6250p Firmware | All versions |
| Qualcomm | Sm7125 Firmware | All versions |
| Qualcomm | Sm7150 Firmware | All versions |
| Qualcomm | Sm7150p Firmware | All versions |
| Qualcomm | Sm7250 Firmware | All versions |
| Qualcomm | Sm7250p Firmware | All versions |
| Qualcomm | Sm8150 Firmware | All versions |
| Qualcomm | Sm8150p Firmware | All versions |
| Qualcomm | Sm8250 Firmware | All versions |
| Qualcomm | Sm8350 Firmware | All versions |
| Qualcomm | Sm8350p Firmware | All versions |
| Qualcomm | Sxr2130 Firmware | All versions |
| Qualcomm | Sxr2130p Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-3632?
How severe is CVE-2020-3632?
How do I fix CVE-2020-3632?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-36314fr-archive-libarchive.c in GNOME file-roller through 3.38.0,…3.9
- CVE-2020-36315In RELIC before 2020-08-01, RSA PKCS#1 v1.5 signature forger…5.3
- CVE-2020-36316In RELIC before 2021-04-03, there is a buffer overflow in PK…5.5
- CVE-2020-36317In the standard library in Rust before 1.49.0, String::retai…7.5
- CVE-2020-36318In the standard library in Rust before 1.49.0, VecDeque::mak…9.8
- CVE-2020-36319Insecure configuration of default ObjectMapper in com.vaadin…6.5
- CVE-2020-36320Unsafe validation RegEx in EmailValidator class in com.vaadi…7.5
- CVE-2020-36321Improper URL validation in development mode handler in com.v…7.5
- CVE-2020-36322An issue was discovered in the FUSE filesystem implementatio…5.5
- CVE-2020-36323In the standard library in Rust before 1.52.0, there is an o…8.2
- CVE-2020-36324Wikimedia Quarry analytics-quarry-web before 2020-12-15 allo…6.1
- CVE-2020-36325An issue was discovered in Jansson through 2.13.1. Due to a …7.5
Are you affected by CVE-2020-3632?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
