CVE-2022-20052
https://notcve.org/view.php?id=CVE-2022-20052
In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS05836642; Issue ID: ALPS05836642. En mdp, se presenta una posible corrupción de memoria debido a un uso de memoria previamente liberada. • https://corp.mediatek.com/product-security-bulletin/April-2022 • CWE-416: Use After Free •
CVE-2022-20067
https://notcve.org/view.php?id=CVE-2022-20067
In mdp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836585; Issue ID: ALPS05836585. En mdp, se presenta una posible escritura fuera de límites debido a una falta de comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/April-2022 • CWE-787: Out-of-bounds Write •
CVE-2022-20062
https://notcve.org/view.php?id=CVE-2022-20062
In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836418; Issue ID: ALPS05836418. En mdp, se presenta una posible corrupción de memoria debido a un uso de memoria previamente liberada. • https://corp.mediatek.com/product-security-bulletin/April-2022 • CWE-416: Use After Free •
CVE-2022-20057
https://notcve.org/view.php?id=CVE-2022-20057
In btif, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06271186; Issue ID: ALPS06271186. En btif, se presenta una posible corrupción de memoria debido a un manejo incorrecto de errores. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-755: Improper Handling of Exceptional Conditions •
CVE-2022-20054
https://notcve.org/view.php?id=CVE-2022-20054
In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219083; Issue ID: ALPS06219083. En ims service, se presenta una posible inyección de comandos AT debido a una falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-862: Missing Authorization •