
CVE-2020-3686
https://notcve.org/view.php?id=CVE-2020-3686
21 Jan 2021 — Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking Un posible problema de memoria fuera del límite durante la reproducción de música cuando un contenido de flujo de... • https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2020-3685
https://notcve.org/view.php?id=CVE-2020-3685
21 Jan 2021 — Pointer variable which is freed is not cleared can result in memory corruption and leads to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking Una variable de puntero que es liberada no es borrada puede resultar en corrupción de la memoria y conllevar a una denegación de servicio en los productos ... • https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin • CWE-415: Double Free •

CVE-2020-11216
https://notcve.org/view.php?id=CVE-2020-11216
21 Jan 2021 — Buffer over read can happen in video driver when playing clip with atomsize having value UINT32_MAX in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Una lectura excesiva del búfer puede ocurrir en el controlador de video cuando se reproduce un clip con un tamaño de átomo que tiene el valor UINT32_MAX en los productos Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivit... • https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin • CWE-125: Out-of-bounds Read CWE-190: Integer Overflow or Wraparound •

CVE-2020-11213
https://notcve.org/view.php?id=CVE-2020-11213
21 Jan 2021 — Out of bound reads might occur in while processing Service descriptor due to improper validation of length of fields in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking Unas lecturas fuera de límites pueden ocurrir mientras se procesa el descriptor de Servicio debido a u... • https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin • CWE-125: Out-of-bounds Read •

CVE-2020-11212
https://notcve.org/view.php?id=CVE-2020-11212
21 Jan 2021 — Out of bounds reads while parsing NAN beacons attributes and OUIs due to improper length of field check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking Unas lecturas fuera de límites mientras se analizan los atributos beacons NAN y las OUI debido a una longitud inapropiada de la comprobac... • https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin • CWE-125: Out-of-bounds Read •

CVE-2020-11197
https://notcve.org/view.php?id=CVE-2020-11197
21 Jan 2021 — Possible integer overflow can occur when stream info update is called when total number of streams detected are zero while parsing TS clip with invalid data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Un posible desbordamiento de enteros puede ocurrir cuando una actualización de la información de la transmisión es llamada cuando el número total de transmisiones detectada... • https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin • CWE-190: Integer Overflow or Wraparound •

CVE-2020-11183
https://notcve.org/view.php?id=CVE-2020-11183
21 Jan 2021 — A process can potentially cause a buffer overflow in the display service allowing privilege escalation by executing code as that service in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Un proceso puede potencialmente causar un desbordamiento del búfer en el servicio de visualización permitiendo una escalada de privilegios al ejecutar código como ese servicio en los productos Snapdragon Auto, Sn... • https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2020-11152
https://notcve.org/view.php?id=CVE-2020-11152
21 Jan 2021 — Race condition in HAL layer while processing callback objects received from HIDL due to lack of synchronization between accessing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Una condición de carrera en la capa HAL al procesar objetos de devolución de llamada recibidos desde HIDL debido a una falta de sincronización entre los objetos de acceso en los productos Snapdragon Auto, Snapdragon ... • https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVE-2020-11148
https://notcve.org/view.php?id=CVE-2020-11148
21 Jan 2021 — Use after free issue in HIDL while using callback to post event in Rx thread when internal mutex is not acquired and meantime close is triggered and callback instance is deleted in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables Un problema de uso de la memoria previamente liberada en HIDL mientras usa la devolución de la llamada para publicar el evento en el subproceso Rx cuando un mutex interno no es ... • https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin • CWE-416: Use After Free •

CVE-2020-11145
https://notcve.org/view.php?id=CVE-2020-11145
21 Jan 2021 — Divide by zero issue can happen while updating delta extension header due to improper validation of master SN and extension header SN in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables Un problema de división por cero puede ocurrir mientras se actualiza el encabezado de la extensión delta debido a una comprobación inapropiada del SN maestro y del encabezado de e... • https://www.qualcomm.com/company/product-security/bulletins/december-2020-bulletin • CWE-369: Divide By Zero •