
CVE-2023-32871
https://notcve.org/view.php?id=CVE-2023-32871
06 May 2024 — In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514. En DA, existe una posible omisión de permiso debido a una verificación de estado incorrecta. • https://corp.mediatek.com/product-security-bulletin/May-2024 • CWE-391: Unchecked Error Condition •

CVE-2023-32873
https://notcve.org/view.php?id=CVE-2023-32873
06 May 2024 — In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08583919; Issue ID: ALPS08304227. En keyInstall, existe una posible escritura fuera de los límites debido a una verificación de los límites faltantes. • https://corp.mediatek.com/product-security-bulletin/May-2024 • CWE-787: Out-of-bounds Write •

CVE-2024-20057
https://notcve.org/view.php?id=CVE-2024-20057
06 May 2024 — In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ID: ALPS08587881. En keyInstall, existe una posible escritura fuera de los límites debido a una verificación de los límites faltantes. • https://corp.mediatek.com/product-security-bulletin/May-2024 • CWE-787: Out-of-bounds Write •

CVE-2024-20054
https://notcve.org/view.php?id=CVE-2024-20054
01 Apr 2024 — In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200. En gnss, existe una posible escalada de privilegios debido a una verificación de los límites faltantes. • https://corp.mediatek.com/product-security-bulletin/April-2024 • CWE-787: Out-of-bounds Write •

CVE-2024-20053
https://notcve.org/view.php?id=CVE-2024-20053
01 Apr 2024 — In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764. En flashc, existe una posible escritura fuera de los límites debido a una excepción no detectada. • https://corp.mediatek.com/product-security-bulletin/April-2024 • CWE-787: Out-of-bounds Write •

CVE-2024-20046
https://notcve.org/view.php?id=CVE-2024-20046
01 Apr 2024 — In battery, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08485622; Issue ID: ALPS08485622. En batería, existe una posible escalada de privilegios debido a un desbordamiento de enteros. • https://corp.mediatek.com/product-security-bulletin/April-2024 • CWE-190: Integer Overflow or Wraparound •

CVE-2024-20034
https://notcve.org/view.php?id=CVE-2024-20034
04 Mar 2024 — In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08488849; Issue ID: ALPS08488849. En la batería, existe una posible escalada de privilegios debido a una verificación de los límites faltantes. • https://corp.mediatek.com/product-security-bulletin/March-2024 • CWE-20: Improper Input Validation •

CVE-2024-20025
https://notcve.org/view.php?id=CVE-2024-20025
04 Mar 2024 — In da, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541686; Issue ID: ALPS08541686. • https://corp.mediatek.com/product-security-bulletin/March-2024 • CWE-190: Integer Overflow or Wraparound •

CVE-2024-20004
https://notcve.org/view.php?id=CVE-2024-20004
05 Feb 2024 — In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW sent invalid NR RRC Connection Setup message, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01191612; Issue ID: MOLY01195812 (MSV-985). En Modem NL1, existe una posible falla del sistema debido a una validación de entrada incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2024 • CWE-20: Improper Input Validation •

CVE-2024-20015
https://notcve.org/view.php?id=CVE-2024-20015
05 Feb 2024 — In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08441419; Issue ID: ALPS08441419. En telephony, existe una posible escalada de privilegios debido a una omisión de permisos. • https://corp.mediatek.com/product-security-bulletin/February-2024 • CWE-305: Authentication Bypass by Primary Weakness •