VYPR

Vendor CVEs

Mediatek

All CVEs

1,198 total · sorted by risk
  • CVE-2025-20651MedMar 3, 2025
    risk 0.27cvss 4.1epss 0.00

    In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID:…

  • CVE-2024-20026MedMar 4, 2024
    risk 0.27cvss 4.2epss 0.00

    In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541632; Issue ID: ALPS08541632.

  • CVE-2023-20847MedSep 4, 2023
    risk 0.27cvss 4.2epss 0.00

    In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354025; Issue ID: ALPS07340108.

  • CVE-2023-20846MedSep 4, 2023
    risk 0.27cvss 4.2epss 0.00

    In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354023; Issue ID: ALPS07340098.

  • CVE-2023-20845MedSep 4, 2023
    risk 0.27cvss 4.2epss 0.00

    In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07197795; Issue ID: ALPS07340357.

  • CVE-2023-20844MedSep 4, 2023
    risk 0.27cvss 4.2epss 0.00

    In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354058; Issue ID: ALPS07340121.

  • CVE-2023-20843MedSep 4, 2023
    risk 0.27cvss 4.2epss 0.00

    In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340119; Issue ID: ALPS07340119.

  • CVE-2023-20839MedSep 4, 2023
    risk 0.27cvss 4.2epss 0.00

    In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326409.

  • CVE-2023-20750MedJun 6, 2023
    risk 0.27cvss 4.1epss 0.00

    In swpm, there is a possible out of bounds write due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07780926; Issue ID: ALPS07780928.

  • CVE-2023-20717MedMay 15, 2023
    risk 0.27cvss 4.1epss 0.00

    In vcu, there is a possible leak of dma buffer due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645185; Issue ID: ALPS07645185.

  • CVE-2023-20620MedMar 7, 2023
    risk 0.27cvss 4.1epss 0.00

    In adsp, there is a possible escalation of privilege due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07554558; Issue ID: ALPS07554558.

  • CVE-2022-32645MedJan 3, 2023
    risk 0.27cvss 4.1epss 0.00

    In vow, there is a possible information disclosure due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494477; Issue ID: ALPS07494477.

  • CVE-2022-20032MedFeb 9, 2022
    risk 0.27cvss 4.1epss 0.00

    In vow driver, there is a possible memory corruption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05852822; Issue ID: ALPS05852822.

  • CVE-2024-20065MedJun 3, 2024
    risk 0.26cvss 4.0epss 0.00

    In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08698617; Issue ID: MSV-1394.

  • CVE-2023-20838MedSep 4, 2023
    risk 0.26cvss 4.0epss 0.00

    In imgsys, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326418.

  • CVE-2025-20643LowFeb 3, 2025
    risk 0.25cvss 3.9epss 0.00

    In DA, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure, if an attacker has physical access to the device, if a malicious actor has already obtained the System privilege. User interaction is needed for…

  • CVE-2024-20038LowMar 4, 2024
    risk 0.22cvss 3.4epss 0.00

    In pq, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08495932; Issue ID: ALPS08495932.

  • CVE-2023-20726LowMay 15, 2023
    risk 0.21cvss 3.3epss 0.00

    In mnld, there is a possible leak of GPS location due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07735968 / ALPS07884552 (For…

  • CVE-2019-15425LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Kata M4s Android device with a build fingerprint of alps/full_hct6750_66_n/hct6750_66_n:7.0/NRD90M/1495624556:user/test-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless…

  • CVE-2019-15423LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Bluboo Bluboo_S1 Android device with a build fingerprint of BLUBOO/Bluboo_S1/Bluboo_S1:7.0/NRD90M/1495809471:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless…

  • CVE-2019-15422LowNov 14, 2019
    risk 0.21cvss 3.3epss 0.00

    The Doogee Mix Android device with a build fingerprint of DOOGEE/MIX/MIX:7.0/NRD90M/1495809471:user/release-keys contains a pre-installed app with a package name of com.mediatek.factorymode app (versionCode=1, versionName=1) that allows unauthorized wireless settings…

  • CVE-2024-20051LowApr 1, 2024
    risk 0.15cvss 2.3epss 0.00

    In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758.

  • CVE-2024-20045LowApr 1, 2024
    risk 0.15cvss 2.3epss 0.00

    In audio, there is a possible out of bounds read due to an incorrect calculation of buffer size. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08024748; Issue ID:…

  • CVE-2026-20494MedAug 3, 2026
    risk 0.00cvss 5.5epss 0.00

    In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314,…

  • CVE-2026-20493MedAug 3, 2026
    risk 0.00cvss 4.4epss 0.00

    In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.

  • CVE-2026-20492MedAug 3, 2026
    risk 0.00cvss 5.5epss 0.00

    In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990,…

  • CVE-2026-20491MedAug 3, 2026
    risk 0.00cvss 5.5epss 0.00

    In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) /…

  • CVE-2026-20490MedAug 3, 2026
    risk 0.00cvss 4.4epss 0.00

    In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.

  • CVE-2026-20489MedAug 3, 2026
    risk 0.00cvss 4.4epss 0.00

    In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID:…

  • CVE-2026-20488MedAug 3, 2026
    risk 0.00cvss 4.4epss 0.00

    In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue…

  • CVE-2026-20484MedAug 3, 2026
    risk 0.00cvss 4.4epss 0.00

    In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue…

  • CVE-2026-20482MedAug 3, 2026
    risk 0.00cvss 6.5epss 0.00

    In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID:…

  • CVE-2026-20480MedAug 3, 2026
    risk 0.00cvss 5.5epss 0.00

    In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D,…

  • CVE-2026-20479HigAug 3, 2026
    risk 0.00cvss 7.5epss 0.01

    In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed…

  • CVE-2026-20478MedAug 3, 2026
    risk 0.00cvss 5.5epss 0.00

    In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988,…

  • CVE-2026-20476MedAug 3, 2026
    risk 0.00cvss 5.5epss 0.00

    In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.

  • CVE-2026-20472MedAug 3, 2026
    risk 0.00cvss 4.4epss 0.00

    In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10991467; Issue ID: MSV-7764.

  • CVE-2026-20471MedAug 3, 2026
    risk 0.00cvss 4.6epss 0.00

    In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2026-20470MedAug 3, 2026
    risk 0.00cvss 6.2epss 0.00

    In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.

  • CVE-2026-20466MedAug 3, 2026
    risk 0.00cvss 6.1epss 0.00

    In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-20463MedJul 1, 2026
    risk 0.00cvss 6.7epss 0.00

    In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01716533; Issue ID:…

  • CVE-2026-20462MedJul 1, 2026
    risk 0.00cvss 6.7epss 0.00

    In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11006447; Issue ID:…

  • CVE-2026-20461MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed…

  • CVE-2026-20460MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is…

  • CVE-2026-20459MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-20458HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.00

    In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not…

  • CVE-2026-20457MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-53854Dec 9, 2025
    risk 0.00cvss epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8186: Fix use-after-free in driver remove path When devm runs function in the "remove" path for a device it runs them in the reverse order. That means that if you have parts of your driver…

Page 24 of 24