CVE-2022-20065
https://notcve.org/view.php?id=CVE-2022-20065
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108658; Issue ID: ALPS06108658. En ccci, se presenta una posible lectura fuera de límites debido a una falta de comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/April-2022 • CWE-125: Out-of-bounds Read •
CVE-2022-20064
https://notcve.org/view.php?id=CVE-2022-20064
In ccci, there is a possible leak of kernel pointer due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108617; Issue ID: ALPS06108617. En ccci, se presenta un posible filtrado de punteros del kernel debido a una comprobación de límites incorrecta. • https://corp.mediatek.com/product-security-bulletin/April-2022 • CWE-125: Out-of-bounds Read •
CVE-2022-20081
https://notcve.org/view.php?id=CVE-2022-20081
In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06461919; Issue ID: ALPS06461919. En A-GPS, se presenta un posible ataque de tipo man in the middle debido a que no han sido comprobados apropiadamente los certificados. • https://corp.mediatek.com/product-security-bulletin/April-2022 • CWE-295: Improper Certificate Validation •