VYPR

Vendor CVEs

Mediatek

All CVEs

1,216 total · sorted by risk
  • CVE-2022-20078MedApr 11, 2022
    risk 0.42cvss 6.4epss 0.00

    In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05852819; Issue ID: ALPS05852819.

  • CVE-2022-20077MedApr 11, 2022
    risk 0.42cvss 6.4epss 0.00

    In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05837742; Issue ID: ALPS05852812.

  • CVE-2022-20063MedApr 11, 2022
    risk 0.42cvss 6.5epss 0.00

    In atf (spm), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06171715; Issue ID: ALPS06171715.

  • CVE-2022-20052MedApr 11, 2022
    risk 0.42cvss 6.5epss 0.00

    In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS05836642; Issue ID: ALPS05836642.

  • CVE-2022-20057MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.00

    In btif, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06271186; Issue ID: ALPS06271186.

  • CVE-2022-20023MedJan 4, 2022
    risk 0.42cvss 6.5epss 0.00

    In Bluetooth, there is a possible application crash due to bluetooth flooding a device with LMP_AU_rand packet. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2022-20022MedJan 4, 2022
    risk 0.42cvss 6.5epss 0.00

    In Bluetooth, there is a possible link disconnection due to bluetooth does not properly handle a connection attempt from a host with the same BD address as the currently connected BT host. This could lead to remote denial of service of bluetooth with no additional execution…

  • CVE-2022-20021MedJan 4, 2022
    risk 0.42cvss 6.5epss 0.00

    In Bluetooth, there is a possible application crash due to bluetooth does not properly handle the reception of multiple LMP_host_connection_req. This could lead to remote denial of service of bluetooth with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20013MedJan 4, 2022
    risk 0.42cvss 6.4epss 0.00

    In vow driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05837742; Issue ID: ALPS05837742.

  • CVE-2021-41789MedJan 4, 2022
    risk 0.42cvss 6.5epss 0.01

    In wifi driver, there is a possible system crash due to a missing validation check. This could lead to remote denial of service from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20190426015;…

  • CVE-2021-41788MedDec 26, 2021
    risk 0.42cvss 6.5epss 0.02

    MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0).

  • CVE-2021-0632MedOct 25, 2021
    risk 0.42cvss 6.5epss 0.00

    In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to a proximal attacker under certain build conditions with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-20055MedApr 1, 2024
    risk 0.41cvss 6.3epss 0.00

    In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.

  • CVE-2023-20851MedSep 4, 2023
    risk 0.41cvss 6.3epss 0.00

    In stc, there is a possible out of bounds read due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08048635; Issue ID: ALPS08048635.

  • CVE-2026-20470MedAug 3, 2026
    risk 0.40cvss 6.2epss 0.00

    In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.

  • CVE-2026-20466MedAug 3, 2026
    risk 0.40cvss 6.1epss 0.00

    In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2024-20136MedDec 2, 2024
    risk 0.40cvss 6.2epss 0.00

    In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09121847; Issue ID: MSV-1821.

  • CVE-2024-20107MedNov 4, 2024
    risk 0.40cvss 6.2epss 0.00

    In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09124360; Issue ID: MSV-1823.

  • CVE-2024-20048MedApr 1, 2024
    risk 0.40cvss 6.2epss 0.00

    In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541769; Issue ID: ALPS08541769.

  • CVE-2026-20498MedAug 3, 2026
    risk 0.39cvss 6.0epss 0.00

    In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493;…

  • CVE-2026-20485MedAug 3, 2026
    risk 0.39cvss 6.0epss 0.00

    In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID:…

  • CVE-2026-20477MedAug 3, 2026
    risk 0.39cvss 6.0epss 0.00

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID:…

  • CVE-2026-20475MedAug 3, 2026
    risk 0.39cvss 6.0epss 0.00

    In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID:…

  • CVE-2026-20474MedAug 3, 2026
    risk 0.39cvss 6.0epss 0.00

    In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID:…

  • CVE-2026-20473MedAug 3, 2026
    risk 0.39cvss 6.0epss 0.00

    In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.

  • CVE-2026-20469MedAug 3, 2026
    risk 0.39cvss 6.0epss 0.00

    In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868;…

  • CVE-2026-20468MedAug 3, 2026
    risk 0.39cvss 6.0epss 0.00

    In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID:…

  • CVE-2026-20467MedAug 3, 2026
    risk 0.39cvss 6.0epss 0.00

    In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue…

  • CVE-2025-68184HigDec 16, 2025
    risk 0.39cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: Disable AFBC support on Mediatek DRM driver Commit c410fa9b07c3 ("drm/mediatek: Add AFBC support to Mediatek DRM driver") added AFBC support to Mediatek DRM and enabled the 32x8/split/sparse…

  • CVE-2025-20658MedApr 7, 2025
    risk 0.39cvss 6.0epss 0.00

    In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2024-20024MedMar 4, 2024
    risk 0.39cvss 6.0epss 0.00

    In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541635; Issue ID: ALPS08541635.

  • CVE-2024-20068MedJun 3, 2024
    risk 0.38cvss 5.9epss 0.01

    In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is no needed for exploitation. Patch ID: MOLY01270721; Issue ID: MSV-1479.

  • CVE-2024-20060MedMay 6, 2024
    risk 0.38cvss 5.9epss 0.00

    In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754.

  • CVE-2024-20019MedMar 4, 2024
    risk 0.38cvss 5.9epss 0.01

    In wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00351241; Issue ID: MSV-1173.

  • CVE-2022-20081MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06461919; Issue ID:…

  • CVE-2025-20670MedMay 5, 2025
    risk 0.37cvss 5.7epss 0.00

    In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with User execution privileges needed. User interaction is needed…

  • CVE-2026-20516MedSep 7, 2026
    risk 0.36cvss 5.5epss 0.00

    In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.

  • CVE-2026-20515MedSep 7, 2026
    risk 0.36cvss 5.5epss 0.00

    In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11122991; Issue ID: MSV-8132.

  • CVE-2026-20500MedSep 7, 2026
    risk 0.36cvss 5.5epss 0.00

    In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.

  • CVE-2026-20494MedAug 3, 2026
    risk 0.36cvss 5.5epss 0.00

    In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314,…

  • CVE-2026-20492MedAug 3, 2026
    risk 0.36cvss 5.5epss 0.00

    In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990,…

  • CVE-2026-20491MedAug 3, 2026
    risk 0.36cvss 5.5epss 0.00

    In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) /…

  • CVE-2026-20480MedAug 3, 2026
    risk 0.36cvss 5.5epss 0.00

    In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D,…

  • CVE-2026-20478MedAug 3, 2026
    risk 0.36cvss 5.5epss 0.00

    In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988,…

  • CVE-2026-20476MedAug 3, 2026
    risk 0.36cvss 5.5epss 0.00

    In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.

  • CVE-2026-20456MedJun 1, 2026
    risk 0.36cvss 5.5epss 0.00

    In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480851; Issue ID: MSV-6338.

  • CVE-2026-20415MedFeb 2, 2026
    risk 0.36cvss 5.5epss 0.00

    In imgsys, there is a possible memory corruption due to improper locking. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10363254; Issue ID: MSV-5617.

  • CVE-2025-20724MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    In wlan AP driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418894; Issue ID: MSV-3475.

  • CVE-2025-20722MedOct 14, 2025
    risk 0.36cvss 5.5epss 0.00

    In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09920036; Issue ID:…

  • CVE-2025-38299MedJul 10, 2025
    risk 0.36cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY() ETDM2_IN_BE and ETDM1_OUT_BE are defined as COMP_EMPTY(), in the case the codec dai_name will be null. Avoid a crash if the device tree is not…

Page 18 of 25