Mediatek Iot Yocto vulnerabilities

24 known vulnerabilities affecting mediatek/iot_yocto.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM21

Vulnerabilities

Page 1 of 2
CVE-2025-20721HIGHCVSS 7.8v25.02025-10-14
CVE-2025-20721 [HIGH] CWE-787 CVE-2025-20721: In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10089545; Issue ID: MSV-4279.
nvd
CVE-2024-20100CRITICALCVSS 9.8v24.02024-10-07
CVE-2024-20100 [CRITICAL] CWE-787 CVE-2024-20100: In wlan driver, there is a possible out of bounds write due to improper input validation. This could In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Issue ID: MSV-1603.
nvd
CVE-2024-20055MEDIUMCVSS 6.3v23.22024-04-01
CVE-2024-20055 [MEDIUM] CWE-125 CVE-2024-20055: In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.
nvd
CVE-2023-32820HIGHCVSS 7.5v23.02023-10-02
CVE-2023-32820 [HIGH] CWE-617 CVE-2023-32820: In wlan firmware, there is a possible firmware assertion due to improper input handling. This could In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.
nvd
CVE-2023-32828MEDIUMCVSS 6.7v23.02023-10-02
CVE-2023-32828 [MEDIUM] CWE-190 CVE-2023-32828: In vpu, there is a possible out of bounds write due to an integer overflow. This could lead to local In vpu, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07767817; Issue ID: ALPS07767817.
nvd
CVE-2023-32829MEDIUMCVSS 6.7v23.02023-10-02
CVE-2023-32829 [MEDIUM] CWE-190 CVE-2023-32829: In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to lo In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07713478; Issue ID: ALPS07713478.
nvd
CVE-2023-32806MEDIUMCVSS 6.7v23.02023-09-04
CVE-2023-32806 [MEDIUM] CWE-787 CVE-2023-32806: In wlan driver, there is a possible out of bounds write due to improper input validation. This could In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441589; Issue ID: ALPS07441589.
nvd
CVE-2023-20841MEDIUMCVSS 6.5v23.02023-09-04
CVE-2023-20841 [MEDIUM] CWE-787 CVE-2023-20841: In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326441.
nvd
CVE-2023-20848MEDIUMCVSS 6.5v23.02023-09-04
CVE-2023-20848 [MEDIUM] CWE-125 CVE-2023-20848: In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This c In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340433.
nvd
CVE-2023-32807MEDIUMCVSS 4.4v23.02023-09-04
CVE-2023-32807 [MEDIUM] CWE-125 CVE-2023-32807: In wlan service, there is a possible out of bounds read due to improper input validation. This could In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588360; Issue ID: ALPS07588360.
nvd
CVE-2023-20849MEDIUMCVSS 6.5v23.02023-09-04
CVE-2023-20849 [MEDIUM] CWE-416 CVE-2023-20849: In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340350.
nvd
CVE-2023-32811MEDIUMCVSS 6.7v23.02023-09-04
CVE-2023-32811 [MEDIUM] CWE-787 CVE-2023-32811: In connectivity system driver, there is a possible out of bounds write due to improper input validat In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID: ALPS07929848.
nvd
CVE-2023-20839MEDIUMCVSS 4.2v23.02023-09-04
CVE-2023-20839 [MEDIUM] CWE-125 CVE-2023-20839: In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326409.
nvd
CVE-2023-20846MEDIUMCVSS 4.2v23.02023-09-04
CVE-2023-20846 [MEDIUM] CWE-125 CVE-2023-20846: In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This c In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354023; Issue ID: ALPS07340098.
nvd
CVE-2023-20844MEDIUMCVSS 4.2v23.02023-09-04
CVE-2023-20844 [MEDIUM] CWE-125 CVE-2023-20844: In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This c In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354058; Issue ID: ALPS07340121.
nvd
CVE-2023-20845MEDIUMCVSS 4.2v23.02023-09-04
CVE-2023-20845 [MEDIUM] CWE-125 CVE-2023-20845: In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07197795; Issue ID: ALPS07340357.
nvd
CVE-2023-20843MEDIUMCVSS 4.2v23.02023-09-04
CVE-2023-20843 [MEDIUM] CWE-125 CVE-2023-20843: In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This c In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340119; Issue ID: ALPS07340119.
nvd
CVE-2023-20842MEDIUMCVSS 6.5v23.02023-09-04
CVE-2023-20842 [MEDIUM] CWE-787 CVE-2023-20842: In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354259; Issue ID: ALPS07340477.
nvd
CVE-2023-20850MEDIUMCVSS 6.5v23.02023-09-04
CVE-2023-20850 [MEDIUM] CWE-787 CVE-2023-20850: In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340381.
nvd
CVE-2023-20835MEDIUMCVSS 6.4v23.02023-09-04
CVE-2023-20835 [MEDIUM] CWE-362 CVE-2023-20835: In camsys, there is a possible use after free due to a race condition. This could lead to local esca In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS07326570.
nvd