CVE-2022-26453
https://notcve.org/view.php?id=CVE-2022-26453
In teei, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06664675; Issue ID: ALPS06664675. En teei, se presenta una posible corrupción de memoria debido a un uso de memoria previamente liberada. • https://corp.mediatek.com/product-security-bulletin/September-2022 • CWE-416: Use After Free •
CVE-2022-26456
https://notcve.org/view.php?id=CVE-2022-26456
In vow, there is a possible information disclosure due to a symbolic link following. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545473; Issue ID: ALPS06545473. En vow, se presenta una posible divulgación de información debido al seguimiento de un enlace simbólico. • https://corp.mediatek.com/product-security-bulletin/September-2022 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •
CVE-2022-26429
https://notcve.org/view.php?id=CVE-2022-26429
In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07025415; Issue ID: ALPS07025415. En cta, se presenta una posible forma de escribir registros de uso de permisos de una aplicación debido a una falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/August-2022 • CWE-862: Missing Authorization •
CVE-2022-21789
https://notcve.org/view.php?id=CVE-2022-21789
In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478101; Issue ID: ALPS06478101. En audio ipi, se presenta una posible corrupción de memoria debido a una condición de carrera. • https://github.com/docfate111/CVE-2022-21789 https://corp.mediatek.com/product-security-bulletin/August-2022 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •
CVE-2022-21784
https://notcve.org/view.php?id=CVE-2022-21784
In WLAN driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06704526; Issue ID: ALPS06704462. En WLAN driver, es posible sea producida una escritura fuera de límites debido a una falta de comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/July-2022 • CWE-787: Out-of-bounds Write •