Filtered by vendor Mediatek Subscriptions
Filtered by product Mediatek Chipset Subscriptions
Total 6 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-20486 1 Mediatek 23 Mediatek Chipset, Mt2718, Mt2718 Firmware and 20 more 2026-08-19 6.7 Medium
In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.
CVE-2026-20496 1 Mediatek 35 Mediatek Chipset, Mt6983, Mt6983 Firmware and 32 more 2026-08-19 4.4 Medium
In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.
CVE-2026-20494 1 Mediatek 7 Mediatek Chipset, Mt6890, Mt6890 Firmware and 4 more 2026-08-19 5.5 Medium
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.
CVE-2026-20466 1 Mediatek 1 Mediatek Chipset 2026-08-04 6.1 Medium
In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For MT2737) / ALPS11072643 (Note: For MT6880, MT6890, MT6990); Issue ID: MSV-6929.
CVE-2026-20433 1 Mediatek 125 Mediatek Chipset, Mt2735, Mt2735 Firmware and 122 more 2026-04-13 8.8 High
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01088681; Issue ID: MSV-4460.
CVE-2026-20446 1 Mediatek 3 Mediatek Chipset, Mt6813, Mt6813 Firmware 2026-04-08 4.3 Medium
In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service, if an attacker has physical access to the device, with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09963054; Issue ID: MSV-3899.