Filtered by vendor Mediatek
Subscribe
Total
1068 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-20504 | 1 Mediatek | 38 Mt2735, Mt2735 Firmware, Mt6833 and 35 more | 2026-09-09 | N/A | 5.3 MEDIUM |
| In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865. | |||||
| CVE-2026-20503 | 1 Mediatek | 114 Mt2716, Mt2716 Firmware, Mt2735 and 111 more | 2026-09-09 | N/A | 5.3 MEDIUM |
| In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue ID: MSV-9020. | |||||
| CVE-2026-20502 | 1 Mediatek | 106 Mt2718, Mt2718 Firmware, Mt6580 and 103 more | 2026-09-09 | N/A | 8.4 HIGH |
| In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196. | |||||
| CVE-2026-20501 | 1 Mediatek | 106 Mt2718, Mt2718 Firmware, Mt6580 and 103 more | 2026-09-09 | N/A | 8.4 HIGH |
| In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197. | |||||
| CVE-2026-20500 | 1 Mediatek | 44 Mt2716, Mt2716 Firmware, Mt6835 and 41 more | 2026-09-09 | N/A | 5.5 MEDIUM |
| In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232. | |||||
| CVE-2026-20478 | 1 Mediatek | 12 Mt2735, Mt2735 Firmware, Mt2737 and 9 more | 2026-08-20 | N/A | 5.5 MEDIUM |
| In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638. | |||||
| CVE-2026-20474 | 1 Mediatek | 34 Mt6991, Mt6991 Firmware, Mt6993 and 31 more | 2026-08-19 | N/A | 6.0 MEDIUM |
| In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758. | |||||
| CVE-2026-20475 | 1 Mediatek | 34 Mt6991, Mt6991 Firmware, Mt6993 and 31 more | 2026-08-19 | N/A | 6.0 MEDIUM |
| In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748. | |||||
| CVE-2026-20476 | 1 Mediatek | 6 Mt6813, Mt6813 Firmware, Mt6986 and 3 more | 2026-08-19 | N/A | 5.5 MEDIUM |
| In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660. | |||||
| CVE-2026-20477 | 1 Mediatek | 20 Mt6991, Mt6991 Firmware, Mt6993 and 17 more | 2026-08-19 | N/A | 6.0 MEDIUM |
| In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID: MSV-7658. | |||||
| CVE-2026-20479 | 1 Mediatek | 38 Mt2735, Mt2735 Firmware, Mt6833 and 35 more | 2026-08-19 | N/A | 7.5 HIGH |
| In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071; Issue ID: MSV-7620. | |||||
| CVE-2026-20480 | 1 Mediatek | 14 Mt2735, Mt2735 Firmware, Mt2737 and 11 more | 2026-08-19 | N/A | 5.5 MEDIUM |
| In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For MT2735, MT3737); Issue ID: MSV-7586. | |||||
| CVE-2026-20481 | 1 Mediatek | 28 Mt6989, Mt6989 Firmware, Mt8755 and 25 more | 2026-08-19 | N/A | 6.0 MEDIUM |
| In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935. | |||||
| CVE-2026-20482 | 1 Mediatek | 10 Mt7902, Mt7902 Firmware, Mt7921 and 7 more | 2026-08-19 | N/A | 6.5 MEDIUM |
| In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824. | |||||
| CVE-2026-20483 | 1 Mediatek | 70 Mt6739, Mt6739 Firmware, Mt6761 and 67 more | 2026-08-19 | N/A | 7.7 HIGH |
| In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243. | |||||
| CVE-2026-20484 | 1 Mediatek | 78 Mt6739, Mt6739 Firmware, Mt6761 and 75 more | 2026-08-19 | N/A | 4.4 MEDIUM |
| In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004. | |||||
| CVE-2026-20485 | 1 Mediatek | 2 Mt6993, Mt6993 Firmware | 2026-08-19 | N/A | 6.0 MEDIUM |
| In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931. | |||||
| CVE-2026-20486 | 1 Mediatek | 22 Mt2718, Mt2718 Firmware, Mt6878 and 19 more | 2026-08-19 | N/A | 6.7 MEDIUM |
| In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833. | |||||
| CVE-2026-20488 | 1 Mediatek | 34 Mt6991, Mt6991 Firmware, Mt6993 and 31 more | 2026-08-19 | N/A | 4.4 MEDIUM |
| In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757. | |||||
| CVE-2026-20489 | 1 Mediatek | 34 Mt6991, Mt6991 Firmware, Mt6993 and 31 more | 2026-08-19 | N/A | 4.4 MEDIUM |
| In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749. | |||||
