CVE-2020-0103
published 2020-05-14CVE-2020-0103: In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This could lead to remote code execution with no…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.61%
73.2th percentile
In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-148107188
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r7hj-hp8c-gmhv: In a2dp_aac_decoder_cleanup of a2dp_aac_decoder
ghsa_unreviewed·2022-05-24
CVE-2020-0103 [HIGH] CWE-119 GHSA-r7hj-hp8c-gmhv: In a2dp_aac_decoder_cleanup of a2dp_aac_decoder
In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-148107188
Android
CVE-2020-0103: Android Security Bulletin 2020-05-01
CVE: CVE-2020-0103
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 9, 10
References: A-148107188
vendor_android·2020-05-01·CVSS 9.8
CVE-2020-0103 [CRITICAL] CVE-2020-0103: Android Security Bulletin 2020-05-01
CVE: CVE-2020-0103
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 9, 10
References: A-148107188
Android Security Bulletin 2020-05-01
CVE: CVE-2020-0103
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 9, 10
References: A-148107188
No detection rules found.
No public exploits indexed.
arXiv
Vulnerability Analysis of the Android Kernel
arxiv_fulltext·2021-12-20
Vulnerability Analysis of the Android Kernel
## Abstract
We describe a workflow used to analyze the source code of the Android OS kernel and rate for a particular kind of bugginess that exposes a program to hacking. The workflow represents a novel approach for components' vulnerability rating.
The approach is inspired by recent work on embedding source code functions.
The workflow combines deep learning with heuristics and machine learning. Deep learning is used to embed function/method labels into a Euclidean space. Because the corpus of Android kernel source code is rather limited (containing approximately 2 million C/C++ functions & Java methods), a straightforward embedding is untenable. To overcome the challenge of the dearth of data, it's necessary to go through an intermediate step of the Byte-Pair Encoding.
Subsequently, we
Checkpoint
11th May – Threat Intelligence Bulletin
blogs_checkpoint·2020-05-11
CVE-2020-8899 11th May – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 11th May – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 11th May 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research have discovered an ongoing cyber espionage operation against government entities in the Asia Pacific (APAC) region. The operation is attributed to the Naikon APT group, using a backdoor dubbed Aria-body to take control of the victims’ networks. One of the attack vectors was infecting a foreign embassy
2020-05-14
Published