
CVE-2023-20829
https://notcve.org/view.php?id=CVE-2023-20829
04 Sep 2023 — In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08014148. En GPS, existe una posible escritura fuera de límites debido a una inexistente comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/September-2023 • CWE-787: Out-of-bounds Write •

CVE-2023-20828
https://notcve.org/view.php?id=CVE-2023-20828
04 Sep 2023 — In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08014144. en gps,existe una posible escritura fuera de límites debido a una comprobación de límites faltantes. Esto podría conducir a una escalada local de privilegios sin necesidad de permisos de ejecución adicionales. • https://corp.mediatek.com/product-security-bulletin/September-2023 • CWE-787: Out-of-bounds Write •

CVE-2023-20826
https://notcve.org/view.php?id=CVE-2023-20826
04 Sep 2023 — In cta, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07978550; Issue ID: ALPS07978550. En cta,existe una posible divulgación de información debido a la falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/September-2023 • CWE-862: Missing Authorization •

CVE-2023-20825
https://notcve.org/view.php?id=CVE-2023-20825
04 Sep 2023 — In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID: ALPS07951413. En duraspeed, existe una posible divulgación de información debido a la falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/September-2023 • CWE-862: Missing Authorization •

CVE-2023-20824
https://notcve.org/view.php?id=CVE-2023-20824
04 Sep 2023 — In duraspeed, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: ALPS07951402; Issue ID: ALPS07951402. En duraspeed, existe una posible divulgación de información debido a la falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/September-2023 • CWE-862: Missing Authorization •

CVE-2023-20821
https://notcve.org/view.php?id=CVE-2023-20821
04 Sep 2023 — In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937113; Issue ID: ALPS07937113. En nvram, existe una posible escritura fuera de límites debido a una inexistente comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/September-2023 • CWE-787: Out-of-bounds Write •

CVE-2023-20812
https://notcve.org/view.php?id=CVE-2023-20812
07 Aug 2023 — In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07944987; Issue ID: ALPS07944987. • https://corp.mediatek.com/product-security-bulletin/August-2023 • CWE-787: Out-of-bounds Write •

CVE-2023-20790
https://notcve.org/view.php?id=CVE-2023-20790
07 Aug 2023 — In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07740194; Issue ID: ALPS07740194. • https://corp.mediatek.com/product-security-bulletin/August-2023 • CWE-787: Out-of-bounds Write •

CVE-2023-20788
https://notcve.org/view.php?id=CVE-2023-20788
07 Aug 2023 — In thermal, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648734; Issue ID: ALPS07648735. • https://corp.mediatek.com/product-security-bulletin/August-2023 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition CWE-416: Use After Free •

CVE-2023-20787
https://notcve.org/view.php?id=CVE-2023-20787
07 Aug 2023 — In thermal, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07648734; Issue ID: ALPS07648734. • https://corp.mediatek.com/product-security-bulletin/August-2023 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition CWE-416: Use After Free •