CVE-2023-20635
https://notcve.org/view.php?id=CVE-2023-20635
In keyinstall, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07563028; Issue ID: ALPS07563028. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-191: Integer Underflow (Wrap or Wraparound) •
CVE-2023-20623
https://notcve.org/view.php?id=CVE-2023-20623
In ion, there is a possible escalation of privilege due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559778; Issue ID: ALPS07559778. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •
CVE-2023-20628
https://notcve.org/view.php?id=CVE-2023-20628
In thermal, there is a possible memory corruption due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494460; Issue ID: ALPS07494460. • https://corp.mediatek.com/product-security-bulletin/March-2023 •
CVE-2023-20630
https://notcve.org/view.php?id=CVE-2023-20630
In usb, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07628505; Issue ID: ALPS07628505. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-787: Out-of-bounds Write •
CVE-2023-20616
https://notcve.org/view.php?id=CVE-2023-20616
In ion, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07560720; Issue ID: ALPS07560720. • https://corp.mediatek.com/product-security-bulletin/February-2023 • CWE-843: Access of Resource Using Incompatible Type ('Type Confusion') •