CVE-2022-20109
https://notcve.org/view.php?id=CVE-2022-20109
In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06399915; Issue ID: ALPS06399915. En ion, se presenta un posible uso de memoria previamente liberada debido a la actualización inapropiada del recuento de referencias. • https://corp.mediatek.com/product-security-bulletin/May-2022 •
CVE-2022-20074
https://notcve.org/view.php?id=CVE-2022-20074
In preloader (partition), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06183301; Issue ID: ALPS06183301. En preloader (partition), se presenta una posible escritura fuera de límites debido a una falta de comprobación de límites. • https://corp.mediatek.com/product-security-bulletin/April-2022 • CWE-125: Out-of-bounds Read CWE-787: Out-of-bounds Write •
CVE-2022-20073
https://notcve.org/view.php?id=CVE-2022-20073
In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160841; Issue ID: ALPS06160841. En preloader (usb), se presenta una posible escritura fuera de límites debido a un desbordamiento de enteros. • https://corp.mediatek.com/product-security-bulletin/April-2022 • CWE-191: Integer Underflow (Wrap or Wraparound) •
CVE-2022-20069
https://notcve.org/view.php?id=CVE-2022-20069
In preloader (usb), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160425; Issue ID: ALPS06160425. En preloader (usb), se presenta una posible escritura fuera de límites debido a un desbordamiento de enteros. • https://corp.mediatek.com/product-security-bulletin/April-2022 • CWE-190: Integer Overflow or Wraparound •