Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2022-20075

    In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05838808; Issue ID: ALPS05... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6875 mt6877 +53 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.6

    MEDIUM
    CVE-2022-20074

    In preloader (partition), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User ... Read more

    Affected Products : android mt6779 mt6833 mt6853 mt6853t mt6873 mt6875 mt6877 mt6879 mt6880 +28 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.6

    MEDIUM
    CVE-2022-20073

    In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interacti... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6873 mt6877 mt6885 mt6893 mt8675 +34 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20072

    In search engine service, there is a possible way to change the default search engine due to an incorrect comparison. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation.... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6789 mt6833 mt6853 mt6853t mt6873 mt6875 +46 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20071

    In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06183315; ... Read more

    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20070

    In ssmr, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06362920; Issue ID: ALP... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6789 mt6833 mt6853 mt6853t mt6873 mt6875 +38 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.6

    MEDIUM
    CVE-2022-20069

    In preloader (usb), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interacti... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6877 mt6885 +37 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20068

    In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06308... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853t mt6873 mt6875 mt6877 mt6880 +46 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20067

    In mdp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836585; Issue ID: ALPS... Read more

    Affected Products : android mt6779 mt6785 mt6833 mt6853 mt6853t mt6873 mt6885 mt6891 mt6893 +37 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2022-20066

    In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0617... Read more

    Affected Products : android mt6785 mt6833 mt6873 mt6875 mt6877 mt6891 mt6739 mt6761 mt6765 +11 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20065

    In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108658; Issue ID: ALPS... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6873 mt6875 mt6877 mt6883 mt6885 +20 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2022-20064

    In ccci, there is a possible leak of kernel pointer due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108617; Issue I... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6789 mt6833 mt6853 mt6873 mt6875 mt6877 +27 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.9

    MEDIUM
    CVE-2022-20063

    In atf (spm), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06171715; Issue ID: A... Read more

    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2022-20062

    In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05836418; Issue ID: ALPS05836418... Read more

    Affected Products : android mt6785 mt6833 mt6853 mt6853t mt6873 mt6877 mt6879 mt6885 mt6891 +27 more products
    • Published: Apr. 11, 2022
    • Modified: Nov. 21, 2024
  • 6.6

    MEDIUM
    CVE-2022-20060

    In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6873 mt6875 mt6877 mt6885 +24 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 6.6

    MEDIUM
    CVE-2022-20059

    In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User intera... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6875 mt6877 +25 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 6.6

    MEDIUM
    CVE-2022-20058

    In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User intera... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6877 mt6885 +23 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2022-20057

    In btif, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06271186; Issue ID: ALPS06... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6883 mt6893 +13 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 6.6

    MEDIUM
    CVE-2022-20056

    In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User intera... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6877 mt6885 +23 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2022-20055

    In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User intera... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6877 mt6885 +23 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294723 Results