Total
380 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-20474 | 1 Mediatek | 34 Mt6991, Mt6991 Firmware, Mt6993 and 31 more | 2026-08-19 | N/A | 6.0 MEDIUM |
| In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758. | |||||
| CVE-2026-20475 | 1 Mediatek | 34 Mt6991, Mt6991 Firmware, Mt6993 and 31 more | 2026-08-19 | N/A | 6.0 MEDIUM |
| In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748. | |||||
| CVE-2026-20481 | 1 Mediatek | 28 Mt6989, Mt6989 Firmware, Mt8755 and 25 more | 2026-08-19 | N/A | 6.0 MEDIUM |
| In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935. | |||||
| CVE-2026-20483 | 1 Mediatek | 70 Mt6739, Mt6739 Firmware, Mt6761 and 67 more | 2026-08-19 | N/A | 7.7 HIGH |
| In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243. | |||||
| CVE-2026-20488 | 1 Mediatek | 34 Mt6991, Mt6991 Firmware, Mt6993 and 31 more | 2026-08-19 | N/A | 4.4 MEDIUM |
| In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757. | |||||
| CVE-2026-20489 | 1 Mediatek | 34 Mt6991, Mt6991 Firmware, Mt6993 and 31 more | 2026-08-19 | N/A | 4.4 MEDIUM |
| In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749. | |||||
| CVE-2026-20497 | 1 Mediatek | 22 Mt6989, Mt6989 Firmware, Mt8755 and 19 more | 2026-08-19 | N/A | 6.0 MEDIUM |
| In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941. | |||||
| CVE-2026-20496 | 1 Mediatek | 34 Mt6983, Mt6983 Firmware, Mt8676 and 31 more | 2026-08-19 | N/A | 4.4 MEDIUM |
| In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132. | |||||
| CVE-2026-20498 | 1 Mediatek | 20 Mt6991, Mt6991 Firmware, Mt8768 and 17 more | 2026-08-19 | N/A | 6.0 MEDIUM |
| In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765. | |||||
| CVE-2026-20473 | 1 Mediatek | 34 Mt6991, Mt6991 Firmware, Mt6993 and 31 more | 2026-08-19 | N/A | 6.0 MEDIUM |
| In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759. | |||||
| CVE-2026-20454 | 1 Mediatek | 72 Mt6739, Mt6739 Firmware, Mt6761 and 69 more | 2026-07-22 | N/A | 6.4 MEDIUM |
| In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786. | |||||
| CVE-2026-20453 | 1 Mediatek | 72 Mt6739, Mt6739 Firmware, Mt6761 and 69 more | 2026-07-22 | N/A | 6.7 MEDIUM |
| In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791. | |||||
| CVE-2026-20455 | 1 Mediatek | 72 Mt6739, Mt6739 Firmware, Mt6761 and 69 more | 2026-07-22 | N/A | 7.8 HIGH |
| In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784. | |||||
| CVE-2026-20451 | 1 Mediatek | 64 Mt2718, Mt2718 Firmware, Mt6899 and 61 more | 2026-06-17 | N/A | 6.7 MEDIUM |
| In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10828685; Issue ID: MSV-6504. | |||||
| CVE-2026-20448 | 1 Mediatek | 44 Mt6765, Mt6765 Firmware, Mt6768 and 41 more | 2026-06-17 | N/A | 6.7 MEDIUM |
| In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10708513; Issue ID: MSV-6281. | |||||
| CVE-2026-20447 | 1 Mediatek | 34 Mt6768, Mt6768 Firmware, Mt6789 and 31 more | 2026-06-17 | N/A | 6.7 MEDIUM |
| In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10724073; Issue ID: MSV-6296. | |||||
| CVE-2026-20444 | 2 Google, Mediatek | 47 Android, Mt6739, Mt6761 and 44 more | 2026-06-17 | N/A | 6.7 MEDIUM |
| In display, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10436995; Issue ID: MSV-5721. | |||||
| CVE-2026-20443 | 2 Google, Mediatek | 47 Android, Mt6739, Mt6761 and 44 more | 2026-06-17 | N/A | 6.7 MEDIUM |
| In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10436998; Issue ID: MSV-5722. | |||||
| CVE-2026-20442 | 2 Google, Mediatek | 47 Android, Mt6739, Mt6761 and 44 more | 2026-06-17 | N/A | 4.4 MEDIUM |
| In display, there is a possible system crash due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10436998; Issue ID: MSV-5723. | |||||
| CVE-2026-20434 | 1 Mediatek | 99 Lr12a, Lr13, Mt2735 and 96 more | 2026-06-17 | N/A | 7.5 HIGH |
| In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY00782946; Issue ID: MSV-4135. | |||||
