Integer overflow in Qualcomm products - CVE-2020-11184
Published: July 7, 2025
Vulnerability identifier: #VU112420
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11184
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to read and manipulate data.
The vulnerability exists due to improper input validation in Video. A remote attacker can read and manipulate data.
Affected software
SM6115P
SXR2130P
SM8350P
SM8350
SM8150P
SM7250P
SM7250
SM7225
SM7125
SM6350
SM6250
SM6125
QCM4290
SM6115
SM4250P
SM4250
SDX55M
SA8155P
SA8155
SA6155
SA6145P
QSM8350
QCS4290
SXR2130
SM8250
SM8150
SDX55
SA6155P
QM215
SXR2130P
SM8350P
SM8350
SM8150P
SM7250P
SM7250
SM7225
SM7125
SM6350
SM6250
SM6125
QCM4290
SM6115
SM4250P
SM4250
SDX55M
SA8155P
SA8155
SA6155
SA6145P
QSM8350
QCS4290
SXR2130
SM8250
SM8150
SDX55
SA6155P
QM215
How to mitigate CVE-2020-11184
Install security update from vendor's website.