Page 70 of 692 results (0.005 seconds)

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 0

In Boa, there is a possible escalation of privilege due to a stack buffer overflow. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210008; Issue ID: OSBNB00123241. • https://corp.mediatek.com/product-security-acknowledgements • CWE-787: Out-of-bounds Write •

CVSS: 6.7EPSS: 0%CPEs: 60EXPL: 0

In Wi-Fi driver, there is a possible undefined behavior due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: GN20220705011; Issue ID: GN20220705011. • https://corp.mediatek.com/product-security-bulletin/February-2023 •

CVSS: 9.8EPSS: 0%CPEs: 4EXPL: 0

In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210009; Issue ID: OSBNB00123234. • https://corp.mediatek.com/product-security-acknowledgements • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 6.4EPSS: 0%CPEs: 40EXPL: 0

In gpu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588678; Issue ID: ALPS07588678. • https://corp.mediatek.com/product-security-bulletin/February-2023 • CWE-662: Improper Synchronization •

CVSS: 6.7EPSS: 0%CPEs: 27EXPL: 0

In vcu, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07519184; Issue ID: ALPS07519184. • https://corp.mediatek.com/product-security-bulletin/February-2023 • CWE-667: Improper Locking •