Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.9

    MEDIUM
    CVE-2022-20052

    In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS05836642; Issue ID: ALPS05836642.... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6877 mt6885 +36 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-20051

    In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6875 mt6877 +53 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20050

    In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0633503... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6875 mt6877 +39 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20049

    In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05954679; Issue... Read more

    Affected Products : android mt6779 mt6785 mt6853 mt6853t mt6873 mt6875 mt6877 mt6883 mt6885 +11 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20048

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS059175... Read more

    Affected Products : android mt6885 mt6893 mt5816 mt5835 mt9900 mt9901 mt9950 mt9969 mt9970 +1 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20047

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS059174... Read more

    Affected Products : android mt6885 mt6893 mt5816 mt5835 mt9900 mt9901 mt9950 mt9969 mt9970 +1 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-20046

    In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06142410; Issue ID: ALPS061... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20045

    In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126820; Issue ID: AL... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20044

    In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126814; Issue ID: AL... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20043

    In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-20042

    In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS061084... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20041

    In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20040

    In power_hal_manager_service, there is a possible permission bypass due to a stack-based buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Pat... Read more

    Affected Products : android mt6779 mt6785 mt6833 mt6853 mt6873 mt6875 mt6877 mt6880 mt6883 +29 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20039

    In ccu driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183345; Issue ID: A... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20038

    In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183335; Issue... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-20037

    In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0617... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6875 mt6877 +47 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-20036

    In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0617... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6875 mt6877 +46 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2022-20035

    In vcu driver, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171675; Issue ID:... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6877 mt6885 +22 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2022-20034

    In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges need... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6873 mt6875 mt6877 mt6885 +12 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2022-20033

    In camera driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862973; Is... Read more

    Affected Products : android mt6779 mt6781 mt6833 mt6853 mt6853t mt6873 mt6877 mt6883 mt6885 +12 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294701 Results