
CVE-2023-20827
https://notcve.org/view.php?id=CVE-2023-20827
04 Sep 2023 — In ims service, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937105; Issue ID: ALPS07937105. En el servicio ims, existe una posible corrupción de memoria debido a una condición de carrera. • https://corp.mediatek.com/product-security-bulletin/September-2023 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CWE-1298: Hardware Logic Contains Race Conditions •

CVE-2023-20826
https://notcve.org/view.php?id=CVE-2023-20826
04 Sep 2023 — In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07978550; Issue ID: ALPS07978550. En cta,existe una posible divulgación de información debido a la falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/September-2023 • CWE-862: Missing Authorization •

CVE-2023-20825
https://notcve.org/view.php?id=CVE-2023-20825
04 Sep 2023 — In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID: ALPS07951413. En duraspeed, existe una posible divulgación de información debido a la falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/September-2023 • CWE-862: Missing Authorization •

CVE-2023-20824
https://notcve.org/view.php?id=CVE-2023-20824
04 Sep 2023 — In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID: ALPS07951402. En duraspeed, existe una posible divulgación de información debido a la falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/September-2023 • CWE-862: Missing Authorization •

CVE-2023-20821
https://notcve.org/view.php?id=CVE-2023-20821
04 Sep 2023 — In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937113; Issue ID: ALPS07937113. En nvram, existe una posible escritura fuera de límites debido a una inexistente comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/September-2023 • CWE-787: Out-of-bounds Write •

CVE-2023-20818
https://notcve.org/view.php?id=CVE-2023-20818
07 Aug 2023 — In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07460540; Issue ID: ALPS07460540. • https://corp.mediatek.com/product-security-bulletin/August-2023 • CWE-125: Out-of-bounds Read •

CVE-2023-20817
https://notcve.org/view.php?id=CVE-2023-20817
07 Aug 2023 — In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453600; Issue ID: ALPS07453600. • https://corp.mediatek.com/product-security-bulletin/August-2023 • CWE-787: Out-of-bounds Write •

CVE-2023-20816
https://notcve.org/view.php?id=CVE-2023-20816
07 Aug 2023 — In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453589; Issue ID: ALPS07453589. • https://corp.mediatek.com/product-security-bulletin/August-2023 • CWE-787: Out-of-bounds Write •

CVE-2023-20815
https://notcve.org/view.php?id=CVE-2023-20815
07 Aug 2023 — In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453587; Issue ID: ALPS07453587. • https://corp.mediatek.com/product-security-bulletin/August-2023 • CWE-787: Out-of-bounds Write •

CVE-2023-20814
https://notcve.org/view.php?id=CVE-2023-20814
07 Aug 2023 — In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07453560; Issue ID: ALPS07453560. • https://corp.mediatek.com/product-security-bulletin/August-2023 • CWE-787: Out-of-bounds Write •