Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2022-20048

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS059175... Read more

    Affected Products : android mt6885 mt6893 mt5816 mt5835 mt9900 mt9901 mt9950 mt9969 mt9970 +1 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20047

    In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS059174... Read more

    Affected Products : android mt6885 mt6893 mt5816 mt5835 mt9900 mt9901 mt9950 mt9969 mt9970 +1 more products
    • Published: Mar. 10, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-20046

    In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06142410; Issue ID: ALPS061... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20045

    In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126820; Issue ID: AL... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20044

    In Bluetooth, there is a possible service crash due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126814; Issue ID: AL... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20043

    In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-20042

    In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS061084... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20041

    In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20040

    In power_hal_manager_service, there is a possible permission bypass due to a stack-based buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Pat... Read more

    Affected Products : android mt6779 mt6785 mt6833 mt6853 mt6873 mt6875 mt6877 mt6880 mt6883 +29 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20039

    In ccu driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183345; Issue ID: A... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20038

    In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183335; Issue... Read more

    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-20037

    In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0617... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6875 mt6877 +47 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2022-20036

    In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS0617... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6875 mt6877 +46 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2022-20035

    In vcu driver, there is a possible information disclosure due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06171675; Issue ID:... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6877 mt6885 +22 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2022-20034

    In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges need... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6873 mt6875 mt6877 mt6885 +12 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2022-20033

    In camera driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05862973; Is... Read more

    Affected Products : android mt6779 mt6781 mt6833 mt6853 mt6853t mt6873 mt6877 mt6883 mt6885 +12 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 4.1

    MEDIUM
    CVE-2022-20032

    In vow driver, there is a possible memory corruption due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05852822; Issue ID: ALPS0... Read more

    Affected Products : android mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6877 mt6883 mt6885 +7 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2022-20031

    In fb driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05850708; Issue ID... Read more

    Affected Products : android mt6779 mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6875 mt6877 +45 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 6.7

    MEDIUM
    CVE-2022-20030

    In vow driver, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05837793;... Read more

    Affected Products : android mt6781 mt6785 mt6833 mt6853 mt6853t mt6873 mt6877 mt6883 mt6885 +7 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2022-20029

    In cmdq driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05747150; Issu... Read more

    Affected Products : android mt6779 mt6785 mt6833 mt6853 mt6853t mt6873 mt6875 mt6877 mt6883 +29 more products
    • Published: Feb. 09, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 294737 Results