Search Results (203 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-20521 2 Mediatek, Mediatek, Inc. 97 Mt2718, Mt2718 Firmware, Mt6768 and 94 more 2026-10-08 8.4 High
In Video HAL, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11375674; Issue ID: MSV-9571.
CVE-2026-20526 2 Mediatek, Mediatek, Inc. 111 Mt2716, Mt2716 Firmware, Mt2735 and 108 more 2026-10-08 7.5 High
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01898195; Issue ID: MSV-8906.
CVE-2026-20527 2 Mediatek, Mediatek, Inc. 111 Mt2716, Mt2716 Firmware, Mt2735 and 108 more 2026-10-08 5.3 Medium
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 / MOLY01210562; Issue ID: MSV-8303.
CVE-2026-20519 2 Mediatek, Mediatek, Inc. 115 Mt2716, Mt2716 Firmware, Mt2735 and 112 more 2026-10-08 7.5 High
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778993; Issue ID: MSV-8898.
CVE-2026-20520 1 Mediatek 115 Mediatek Chipset, Mt2716, Mt2716 Firmware and 112 more 2026-10-08 7.5 High
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778988; Issue ID: MSV-8897.
CVE-2026-20543 2 Mediatek, Mediatek, Inc. 167 Mt2716, Mt2716 Firmware, Mt2735 and 164 more 2026-10-08 5.5 Medium
In Modem, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01645293; Issue ID: MSV-6761.
CVE-2026-20503 2 Mediatek, Mediatek, Inc. 115 Mt2716, Mt2716 Firmware, Mt2735 and 112 more 2026-09-09 5.3 Medium
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue ID: MSV-9020.
CVE-2026-20502 2 Mediatek, Mediatek, Inc. 107 Mt2718, Mt2718 Firmware, Mt6580 and 104 more 2026-09-09 8.4 High
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.
CVE-2026-20501 2 Mediatek, Mediatek, Inc. 107 Mt2718, Mt2718 Firmware, Mt6580 and 104 more 2026-09-09 8.4 High
In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197.
CVE-2026-20481 2 Mediatek, Mediatek, Inc. 29 Mt6989, Mt6989 Firmware, Mt8755 and 26 more 2026-08-19 6 Medium
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.
CVE-2026-20483 2 Mediatek, Mediatek, Inc. 71 Mt6739, Mt6739 Firmware, Mt6761 and 68 more 2026-08-19 7.7 High
In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.
CVE-2026-20484 2 Mediatek, Mediatek, Inc. 79 Mt6739, Mt6739 Firmware, Mt6761 and 76 more 2026-08-19 4.4 Medium
In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.
CVE-2026-20497 2 Mediatek, Mediatek, Inc. 23 Mt6989, Mt6989 Firmware, Mt8755 and 20 more 2026-08-19 6 Medium
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.
CVE-2026-20453 2 Mediatek, Mediatek, Inc. 73 Mt6739, Mt6739 Firmware, Mt6761 and 70 more 2026-06-01 6.7 Medium
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791.
CVE-2026-20454 2 Mediatek, Mediatek, Inc. 73 Mt6739, Mt6739 Firmware, Mt6761 and 70 more 2026-06-01 6.4 Medium
In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786.
CVE-2026-20455 2 Mediatek, Mediatek, Inc. 73 Mt6739, Mt6739 Firmware, Mt6761 and 70 more 2026-06-01 7.8 High
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784.
CVE-2026-20447 2 Mediatek, Mediatek, Inc. 35 Mt6768, Mt6768 Firmware, Mt6789 and 32 more 2026-05-07 6.7 Medium
In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296.
CVE-2026-20448 2 Mediatek, Mediatek, Inc. 45 Mt6765, Mt6765 Firmware, Mt6768 and 42 more 2026-05-07 6.7 Medium
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281.
CVE-2026-20449 2 Mediatek, Mediatek, Inc. 137 Mt2735, Mt2735 Firmware, Mt2737 and 134 more 2026-05-07 6.5 Medium
In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue ID: MSV-6148.
CVE-2026-20450 2 Mediatek, Mediatek, Inc. 103 Mt2735, Mt2735 Firmware, Mt2737 and 100 more 2026-05-07 6.5 Medium
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620; Issue ID: MSV-6100.