CVE-2022-47461
https://notcve.org/view.php?id=CVE-2022-47461
In telephone service, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. • https://www.unisoc.com/en_us/secy/announcementDetail/1632612109718192129 • CWE-862: Missing Authorization •
CVE-2022-47460
https://notcve.org/view.php?id=CVE-2022-47460
In gpu device, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel. • https://www.unisoc.com/en_us/secy/announcementDetail/1632612109718192129 • CWE-416: Use After Free •
CVE-2023-20635
https://notcve.org/view.php?id=CVE-2023-20635
In keyinstall, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07563028; Issue ID: ALPS07563028. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-191: Integer Underflow (Wrap or Wraparound) •
CVE-2023-20626
https://notcve.org/view.php?id=CVE-2023-20626
In msdc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07405223; Issue ID: ALPS07405223. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-20: Improper Input Validation •
CVE-2023-20623
https://notcve.org/view.php?id=CVE-2023-20623
In ion, there is a possible escalation of privilege due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07559778; Issue ID: ALPS07559778. • https://corp.mediatek.com/product-security-bulletin/March-2023 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •