Page 21 of 126 results (0.011 seconds)

CVSS: 7.8EPSS: 0%CPEs: 63EXPL: 0

In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219097; Issue ID: ALPS06219097. En ims service, se presenta una posible escalada de privilegios debido a una falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-862: Missing Authorization •

CVSS: 7.8EPSS: 0%CPEs: 40EXPL: 0

In power_hal_manager_service, there is a possible permission bypass due to a stack-based buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219150; Issue ID: ALPS06219150. En power_hal_manager_service, se presenta una posible omisión de permisos debido a un desbordamiento del búfer en la región stack de la memoria. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-787: Out-of-bounds Write •

CVSS: 5.5EPSS: 0%CPEs: 57EXPL: 0

In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171689; Issue ID: ALPS06171689. En ion driver, se presenta una posible divulgación de información debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-20: Improper Input Validation •

CVSS: 5.5EPSS: 0%CPEs: 58EXPL: 0

In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171705; Issue ID: ALPS06171705. En ion driver, se presenta una posible divulgación de información debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-20: Improper Input Validation •

CVSS: 6.8EPSS: 0%CPEs: 22EXPL: 0

In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160806. En Preloader XFLASH, se presenta una posible escalada de privilegios debido a una comprobación inapropiada del certificado. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-295: Improper Certificate Validation •