
CVE-2022-20062
https://notcve.org/view.php?id=CVE-2022-20062
11 Apr 2022 — In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836418; Issue ID: ALPS05836418. En mdp, se presenta una posible corrupción de memoria debido a un uso de memoria previamente liberada. • https://corp.mediatek.com/product-security-bulletin/April-2022 • CWE-416: Use After Free •

CVE-2022-20060
https://notcve.org/view.php?id=CVE-2022-20060
09 Mar 2022 — In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06137462. En preloader (usb), se presenta una posible omisión de permisos debido a una falta de autenticación de imagen apropiada. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-306: Missing Authentication for Critical Function •

CVE-2022-20059
https://notcve.org/view.php?id=CVE-2022-20059
09 Mar 2022 — In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160781. En preloader (usb), se presenta una posible escritura fuera de límites debido a una falta de comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-787: Out-of-bounds Write •

CVE-2022-20058
https://notcve.org/view.php?id=CVE-2022-20058
09 Mar 2022 — In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160485. En preloader (usb), se presenta una posible escritura fuera de límites debido a una falta de comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-787: Out-of-bounds Write •

CVE-2022-20056
https://notcve.org/view.php?id=CVE-2022-20056
09 Mar 2022 — In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160820. En preloader (usb), es posible que sea producida una escritura fuera de límites debido a una falta de comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-787: Out-of-bounds Write •

CVE-2022-20055
https://notcve.org/view.php?id=CVE-2022-20055
09 Mar 2022 — In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160830. En preloader (usb), se presenta una posible escritura fuera de límites debido a una falta de comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-787: Out-of-bounds Write •

CVE-2022-20050
https://notcve.org/view.php?id=CVE-2022-20050
09 Mar 2022 — In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06335038; Issue ID: ALPS06335038. En connsyslogger, se presenta un posible seguimiento de enlaces simbólicos debido a una resolución inapropiada de enlaces. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVE-2022-20029
https://notcve.org/view.php?id=CVE-2022-20029
09 Feb 2022 — In cmdq driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05747150; Issue ID: ALPS05747150. En cmdq driver, se presenta una posible lectura fuera de límites debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-125: Out-of-bounds Read •

CVE-2021-0676
https://notcve.org/view.php?id=CVE-2021-0676
17 Dec 2021 — In geniezone driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05863009; Issue ID: ALPS05863009. En el controlador geniezone, se presenta una posible lectura fuera de límites debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/December-2021 • CWE-125: Out-of-bounds Read •

CVE-2021-0624
https://notcve.org/view.php?id=CVE-2021-0624
18 Nov 2021 — In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05594988; Issue ID: ALPS05594988. En flv extractor, se presenta una posible lectura fuera de límites debido a un desbordamiento del búfer de la pila. • https://corp.mediatek.com/product-security-bulletin/November-2021 • CWE-125: Out-of-bounds Read •