Search
Search Results (13 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-20529 | 2 Mediatek, Mediatek, Inc. | 57 Mt6761, Mt6761 Firmware, Mt6765 and 54 more | 2026-10-09 | 6.7 Medium |
| In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11276677; Issue ID: MSV-9217. | ||||
| CVE-2026-20533 | 1 Mediatek | 67 Mediatek Chipset, Mt6739, Mt6739 Firmware and 64 more | 2026-10-09 | 6.7 Medium |
| In display, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11296678; Issue ID: MSV-9167. | ||||
| CVE-2026-20534 | 2 Mediatek, Mediatek, Inc. | 167 Mt2716, Mt2716 Firmware, Mt2735 and 164 more | 2026-10-09 | 5.3 Medium |
| In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01797547; Issue ID: MSV-9155. | ||||
| CVE-2026-20543 | 2 Mediatek, Mediatek, Inc. | 167 Mt2716, Mt2716 Firmware, Mt2735 and 164 more | 2026-10-08 | 5.5 Medium |
| In Modem, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01645293; Issue ID: MSV-6761. | ||||
| CVE-2026-20502 | 2 Mediatek, Mediatek, Inc. | 107 Mt2718, Mt2718 Firmware, Mt6580 and 104 more | 2026-09-09 | 8.4 High |
| In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196. | ||||
| CVE-2026-20501 | 2 Mediatek, Mediatek, Inc. | 107 Mt2718, Mt2718 Firmware, Mt6580 and 104 more | 2026-09-09 | 8.4 High |
| In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197. | ||||
| CVE-2026-20483 | 2 Mediatek, Mediatek, Inc. | 71 Mt6739, Mt6739 Firmware, Mt6761 and 68 more | 2026-08-19 | 7.7 High |
| In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243. | ||||
| CVE-2026-20484 | 2 Mediatek, Mediatek, Inc. | 79 Mt6739, Mt6739 Firmware, Mt6761 and 76 more | 2026-08-19 | 4.4 Medium |
| In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004. | ||||
| CVE-2026-20453 | 2 Mediatek, Mediatek, Inc. | 73 Mt6739, Mt6739 Firmware, Mt6761 and 70 more | 2026-06-01 | 6.7 Medium |
| In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791. | ||||
| CVE-2026-20454 | 2 Mediatek, Mediatek, Inc. | 73 Mt6739, Mt6739 Firmware, Mt6761 and 70 more | 2026-06-01 | 6.4 Medium |
| In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786. | ||||
| CVE-2026-20455 | 2 Mediatek, Mediatek, Inc. | 73 Mt6739, Mt6739 Firmware, Mt6761 and 70 more | 2026-06-01 | 7.8 High |
| In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784. | ||||
| CVE-2026-20449 | 2 Mediatek, Mediatek, Inc. | 137 Mt2735, Mt2735 Firmware, Mt2737 and 134 more | 2026-05-07 | 6.5 Medium |
| In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue ID: MSV-6148. | ||||
| CVE-2025-20659 | 1 Mediatek | 170 Mt2735, Mt2735 Firmware, Mt2737 and 167 more | 2026-02-17 | 6.5 Medium |
| In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01519028; Issue ID: MSV-2768. | ||||
Page 1 of 1.