CVE-2022-32642
https://notcve.org/view.php?id=CVE-2022-32642
In ccd, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07326547; Issue ID: ALPS07326547. • https://corp.mediatek.com/product-security-bulletin/February-2023 • CWE-662: Improper Synchronization •
CVE-2023-20612
https://notcve.org/view.php?id=CVE-2023-20612
In ril, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07629571; Issue ID: ALPS07629571. • https://corp.mediatek.com/product-security-bulletin/February-2023 • CWE-20: Improper Input Validation •
CVE-2021-31575
https://notcve.org/view.php?id=CVE-2021-31575
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210009; Issue ID: OSBNB00123234. • https://corp.mediatek.com/product-security-acknowledgements • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2022-32643
https://notcve.org/view.php?id=CVE-2022-32643
In ccd, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS07341261. • https://corp.mediatek.com/product-security-bulletin/February-2023 • CWE-662: Improper Synchronization •
CVE-2023-20602
https://notcve.org/view.php?id=CVE-2023-20602
In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494107; Issue ID: ALPS07494107. • https://corp.mediatek.com/product-security-bulletin/February-2023 • CWE-190: Integer Overflow or Wraparound •