VYPR

ion

by Mediatek

CVEs (7)

  • CVE-2022-20111HigMay 3, 2022
    risk 0.55cvss 8.4epss 0.00

    In ion, there is a possible use after free due to incorrect error handling. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366069; Issue ID: ALPS06366069.

  • CVE-2022-21743HigMay 3, 2022
    risk 0.51cvss 7.8epss 0.00

    In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06371108; Issue ID: ALPS06371108.

  • CVE-2022-20109HigMay 3, 2022
    risk 0.51cvss 7.8epss 0.00

    In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06399915; Issue ID: ALPS06399915.

  • CVE-2022-20110HigMay 3, 2022
    risk 0.46cvss 7.0epss 0.00

    In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06399915; Issue ID: ALPS06399901.

  • CVE-2023-20768MedJul 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07559800.

  • CVE-2023-20616MedFeb 6, 2023
    risk 0.44cvss 6.7epss 0.00

    In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07560720.

  • CVE-2023-20623MedMar 7, 2023
    risk 0.42cvss 6.4epss 0.00

    In ion, there is a possible escalation of privilege due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559778; Issue ID: ALPS07559778.