Page 77 of 2012 results (0.010 seconds)

CVSS: 6.7EPSS: 0%CPEs: 15EXPL: 0

In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. • https://www.unisoc.com/en_us/secy/announcementDetail/1621031430231134210 • CWE-862: Missing Authorization •

CVSS: 4.7EPSS: 0%CPEs: 15EXPL: 0

In wlan driver, there is a race condition. This could lead to local denial of service in wlan services. • https://www.unisoc.com/en_us/secy/announcementDetail/1621031430231134210 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 6.7EPSS: 0%CPEs: 16EXPL: 0

In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalation of privilege with system execution privileges needed. • https://www.unisoc.com/en_us/secy/announcementDetail/1621031430231134210 • CWE-862: Missing Authorization •

CVSS: 6.7EPSS: 0%CPEs: 28EXPL: 0

In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494107; Issue ID: ALPS07494107. • https://corp.mediatek.com/product-security-bulletin/February-2023 • CWE-190: Integer Overflow or Wraparound •

CVSS: 4.4EPSS: 0%CPEs: 35EXPL: 0

In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446236; Issue ID: ALPS07446236. • https://corp.mediatek.com/product-security-bulletin/December-2022 • CWE-125: Out-of-bounds Read •