Page 84 of 3966 results (0.008 seconds)

CVSS: 6.7EPSS: 0%CPEs: 15EXPL: 0

In engineermode services, there is a missing permission check. This could lead to local escalation of privilege with system execution privileges needed. • https://www.unisoc.com/en_us/secy/announcementDetail/1621031430231134210 • CWE-862: Missing Authorization •

CVSS: 4.7EPSS: 0%CPEs: 15EXPL: 0

In wlan driver, there is a race condition. This could lead to local denial of service in wlan services. • https://www.unisoc.com/en_us/secy/announcementDetail/1621031430231134210 • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') •

CVSS: 6.7EPSS: 0%CPEs: 16EXPL: 0

In cmd services, there is a OS command injection issue due to missing permission check. This could lead to local escalation of privilege with system execution privileges needed. • https://www.unisoc.com/en_us/secy/announcementDetail/1621031430231134210 • CWE-862: Missing Authorization •

CVSS: 6.7EPSS: 0%CPEs: 28EXPL: 0

In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07494107; Issue ID: ALPS07494107. • https://corp.mediatek.com/product-security-bulletin/February-2023 • CWE-190: Integer Overflow or Wraparound •

CVSS: 4.4EPSS: 0%CPEs: 35EXPL: 0

In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07446236; Issue ID: ALPS07446236. • https://corp.mediatek.com/product-security-bulletin/December-2022 • CWE-125: Out-of-bounds Read •