
CVE-2022-20053
https://notcve.org/view.php?id=CVE-2022-20053
09 Mar 2022 — In ims service, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219097; Issue ID: ALPS06219097. En ims service, se presenta una posible escalada de privilegios debido a una falta de comprobación de permisos. • https://corp.mediatek.com/product-security-bulletin/March-2022 • CWE-862: Missing Authorization •

CVE-2022-20040
https://notcve.org/view.php?id=CVE-2022-20040
09 Feb 2022 — In power_hal_manager_service, there is a possible permission bypass due to a stack-based buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06219150; Issue ID: ALPS06219150. En power_hal_manager_service, se presenta una posible omisión de permisos debido a un desbordamiento del búfer en la región stack de la memoria. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-787: Out-of-bounds Write •

CVE-2022-20037
https://notcve.org/view.php?id=CVE-2022-20037
09 Feb 2022 — In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171705; Issue ID: ALPS06171705. En ion driver, se presenta una posible divulgación de información debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-20: Improper Input Validation •

CVE-2022-20036
https://notcve.org/view.php?id=CVE-2022-20036
09 Feb 2022 — In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171689; Issue ID: ALPS06171689. En ion driver, se presenta una posible divulgación de información debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/February-2022 • CWE-20: Improper Input Validation •

CVE-2021-40148
https://notcve.org/view.php?id=CVE-2021-40148
04 Jan 2022 — In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00716585; Issue ID: ALPS05886933. En el módem EMM, se presenta una posible divulgación de información debido a una falta de cifrado de datos. • https://corp.mediatek.com/product-security-bulletin/January-2022 • CWE-319: Cleartext Transmission of Sensitive Information •