CVE-2022-20068
https://notcve.org/view.php?id=CVE-2022-20068
In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308907; Issue ID: ALPS06308907. En mobile_log_d, se presenta un posible seguimiento de enlaces simbólicos debido a una resolución de enlaces inapropiada. • https://corp.mediatek.com/product-security-bulletin/April-2022 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2022-20051
https://notcve.org/view.php?id=CVE-2022-20051
In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219127; Issue ID: ALPS06219127. En ims service, se presenta un posible comportamiento no esperado de la aplicación debido a una asignación de privilegios incorrecta. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-269: Improper Privilege Management •
CVE-2022-20050
https://notcve.org/view.php?id=CVE-2022-20050
In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06335038; Issue ID: ALPS06335038. En connsyslogger, se presenta un posible seguimiento de enlaces simbólicos debido a una resolución inapropiada de enlaces. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2022-20053
https://notcve.org/view.php?id=CVE-2022-20053
In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219097; Issue ID: ALPS06219097. En ims service, se presenta una posible escalada de privilegios debido a una falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-862: Missing Authorization •
CVE-2022-20036
https://notcve.org/view.php?id=CVE-2022-20036
In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171689; Issue ID: ALPS06171689. En ion driver, se presenta una posible divulgación de información debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-20: Improper Input Validation •