CVE-2022-20037
https://notcve.org/view.php?id=CVE-2022-20037
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171705; Issue ID: ALPS06171705. En ion driver, se presenta una posible divulgación de información debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-20: Improper Input Validation •
CVE-2022-20035
https://notcve.org/view.php?id=CVE-2022-20035
In vcu driver, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171675; Issue ID: ALPS06171675. En vcu driver, se presenta una posible divulgación de información debido a un uso de memoria previamente liberada. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-416: Use After Free •
CVE-2022-20034
https://notcve.org/view.php?id=CVE-2022-20034
In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160806. En Preloader XFLASH, se presenta una posible escalada de privilegios debido a una comprobación inapropiada del certificado. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-295: Improper Certificate Validation •
CVE-2022-20033
https://notcve.org/view.php?id=CVE-2022-20033
In camera driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862973; Issue ID: ALPS05862973. En vow driver, se presenta una posible lectura fuera de límites debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-125: Out-of-bounds Read •
CVE-2022-20017
https://notcve.org/view.php?id=CVE-2022-20017
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862991; Issue ID: ALPS05862991. En ion driver, se presenta una posible divulgación de información debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-20: Improper Input Validation •