
Cloud Vulnerability DB
A community-led vulnerabilities database
In libDRCdec, there is a possible information disclosure vulnerability (CVE-2020-0361) affecting Android 11. The vulnerability was disclosed in September 2020 and stems from uninitialized data usage. This security flaw affects Android systems and requires user interaction for exploitation (NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 6.5 (Medium), with the following vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. The vulnerability exists in the libDRCdec component and is related to uninitialized data handling. The technical nature of the flaw indicates that it could lead to information disclosure without requiring additional execution privileges (NVD).
If successfully exploited, this vulnerability could lead to remote information disclosure. The impact is limited to confidentiality, with no direct effect on integrity or availability of the system. User interaction is required for successful exploitation (NVD).
The vulnerability requires user interaction for exploitation, suggesting that some form of social engineering or user action is necessary to trigger the vulnerability. The attack complexity is rated as low, indicating that the attack can be performed with standard methods (NVD).
The vulnerability has been addressed in Android 11. Users should ensure their devices are updated to the latest available version that includes the security patch (Android Security Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."