CVE-2020-3686: Critical severity android vulnerability
Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3686?
CVE-2020-3686 has been assigned a CVSS severity score that indicates significant risk due to potential memory out of bounds issues during media playback.
How do I fix CVE-2020-3686?
To fix CVE-2020-3686, it is essential to apply the latest firmware updates provided by Qualcomm or your device manufacturer.
What systems are affected by CVE-2020-3686?
CVE-2020-3686 affects various Qualcomm Snapdragon components used across multiple products, including Android devices.
What kind of attack does CVE-2020-3686 enable?
CVE-2020-3686 could potentially allow remote attackers to execute arbitrary code through crafted media files during playback.
When was CVE-2020-3686 disclosed?
CVE-2020-3686 was disclosed in December 2020, as part of a broader security bulletin announcing vulnerabilities in Qualcomm products.