
CVE-2023-20655
https://notcve.org/view.php?id=CVE-2023-20655
06 Apr 2023 — In mmsdk, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203022; Issue ID: ALPS07203022. • https://corp.mediatek.com/product-security-bulletin/April-2023 • CWE-269: Improper Privilege Management •

CVE-2023-20664
https://notcve.org/view.php?id=CVE-2023-20664
06 Apr 2023 — In gz, there is a possible double free due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07505952; Issue ID: ALPS07505952. • https://corp.mediatek.com/product-security-bulletin/April-2023 • CWE-416: Use After Free •

CVE-2023-20665
https://notcve.org/view.php?id=CVE-2023-20665
06 Apr 2023 — In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628604; Issue ID: ALPS07628604. • https://corp.mediatek.com/product-security-bulletin/April-2023 • CWE-125: Out-of-bounds Read •

CVE-2023-20635
https://notcve.org/view.php?id=CVE-2023-20635
07 Mar 2023 — In keyinstall, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07563028; Issue ID: ALPS07563028. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-191: Integer Underflow (Wrap or Wraparound) •

CVE-2023-20639
https://notcve.org/view.php?id=CVE-2023-20639
07 Mar 2023 — In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628587; Issue ID: ALPS07628587. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-20: Improper Input Validation •

CVE-2023-20646
https://notcve.org/view.php?id=CVE-2023-20646
07 Mar 2023 — In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628536; Issue ID: ALPS07628536. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-20: Improper Input Validation •

CVE-2023-20638
https://notcve.org/view.php?id=CVE-2023-20638
07 Mar 2023 — In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628537; Issue ID: ALPS07628537. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-20: Improper Input Validation •

CVE-2023-20628
https://notcve.org/view.php?id=CVE-2023-20628
07 Mar 2023 — In thermal, there is a possible memory corruption due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494460; Issue ID: ALPS07494460. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-248: Uncaught Exception •

CVE-2023-20642
https://notcve.org/view.php?id=CVE-2023-20642
07 Mar 2023 — In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628586; Issue ID: ALPS07628586. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-20: Improper Input Validation •

CVE-2023-20647
https://notcve.org/view.php?id=CVE-2023-20647
07 Mar 2023 — In ril, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628547; Issue ID: ALPS07628547. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-20: Improper Input Validation •