Mediatek Inc Mediatek Chipset vulnerabilities
74 known vulnerabilities affecting mediatek_inc/mediatek_chipset.
Total CVEs
74
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH22MEDIUM50
Vulnerabilities
Page 3 of 4
CVE-2026-20410MEDIUMCVSS 6.7vMT6897vMT6989+3 more2026-02-02
CVE-2026-20410 [MEDIUM] CWE-787 CVE-2026-20410: In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10362552; Issue ID: MSV-5760.
cvelistv5nvd
CVE-2026-20405MEDIUMCVSS 6.5vMT2735vMT2737+50 more2026-02-02
CVE-2026-20405 [MEDIUM] CWE-617 CVE-2026-20405: In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01688495; Issue ID: MSV-4818.
cvelistv5nvd
CVE-2026-20420MEDIUMCVSS 6.5vMT2735vMT2737+34 more2026-02-02
CVE-2026-20420 [MEDIUM] CWE-125 CVE-2026-20420: In Modem, there is a possible system crash due to incorrect error handling. This could lead to remot
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738313; Issue ID: MSV-5935.
cvelistv5nvd
CVE-2026-20413MEDIUMCVSS 6.7vMT6899vMT6991+2 more2026-02-02
CVE-2026-20413 [MEDIUM] CWE-1285 CVE-2026-20413: In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10362725; Issue ID: MSV-5694.
cvelistv5nvd
CVE-2026-20422MEDIUMCVSS 6.5vMT2735vMT2737+51 more2026-02-02
CVE-2026-20422 [MEDIUM] CWE-617 CVE-2026-20422: In Modem, there is a possible system crash due to improper input validation. This could lead to remo
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00827332; Issue ID: MSV-5919.
cvelistv5nvd
CVE-2026-20404MEDIUMCVSS 6.5vMT2735vMT2737+50 more2026-02-02
CVE-2026-20404 [MEDIUM] CWE-787 CVE-2026-20404: In Modem, there is a possible system crash due to improper input validation. This could lead to remo
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689248; Issue ID: MSV-4837.
cvelistv5nvd
CVE-2025-20779HIGHCVSS 7.0vMT6739vMT6761+43 more2026-01-06
CVE-2025-20779 [HIGH] CWE-416 CVE-2025-20779: In display, there is a possible use after free due to a race condition. This could lead to local esc
In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184084; Issue ID: MSV-4720.
cvelistv5nvd
CVE-2025-20781HIGHCVSS 7.8vMT6739vMT6761+43 more2026-01-06
CVE-2025-20781 [HIGH] CWE-415 CVE-2025-20781: In display, there is a possible memory corruption due to use after free. This could lead to local es
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182914; Issue ID: MSV-4699.
cvelistv5nvd
CVE-2025-20797HIGHCVSS 7.8vMT2718vMT6765+32 more2026-01-06
CVE-2025-20797 [HIGH] CWE-121 CVE-2025-20797: In battery, there is a possible out of bounds write due to a missing bounds check. This could lead t
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5534.
cvelistv5nvd
CVE-2025-20795HIGHCVSS 7.8vMT2718vMT6580+52 more2026-01-06
CVE-2025-20795 [HIGH] CWE-787 CVE-2025-20795: In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lea
In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10276761; Issue ID: MSV-5141.
cvelistv5nvd
CVE-2025-20798HIGHCVSS 7.8vMT2718vMT6765+32 more2026-01-06
CVE-2025-20798 [HIGH] CWE-787 CVE-2025-20798: In battery, there is a possible out of bounds write due to a missing bounds check. This could lead t
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5533.
cvelistv5nvd
CVE-2025-20801HIGHCVSS 7.0vMT6878vMT6897+8 more2026-01-06
CVE-2025-20801 [HIGH] CWE-415 CVE-2025-20801: In seninf, there is a possible memory corruption due to a race condition. This could lead to local e
In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10251210; Issue ID: MSV-4926.
cvelistv5nvd
CVE-2025-20796HIGHCVSS 7.8vMT6989vMT8796+1 more2026-01-06
CVE-2025-20796 [HIGH] CWE-1285 CVE-2025-20796: In imgsys, there is a possible out of bounds write due to improper input validation. This could lead
In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10314745; Issue ID: MSV-5553.
cvelistv5nvd
CVE-2025-20799HIGHCVSS 7.8vMT6899vMT6991+2 more2026-01-06
CVE-2025-20799 [HIGH] CWE-416 CVE-2025-20799: In c2ps, there is a possible memory corruption due to use after free. This could lead to local escal
In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10274607; Issue ID: MSV-5049.
cvelistv5nvd
CVE-2025-20778HIGHCVSS 7.8vMT6739vMT6761+43 more2026-01-06
CVE-2025-20778 [HIGH] CWE-787 CVE-2025-20778: In display, there is a possible out of bounds write due to a missing bounds check. This could lead t
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184870; Issue ID: MSV-4729.
cvelistv5nvd
CVE-2025-20800HIGHCVSS 7.8vMT2718vMT6899+4 more2026-01-06
CVE-2025-20800 [HIGH] CWE-787 CVE-2025-20800: In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead t
In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10267349; Issue ID: MSV-5033.
cvelistv5nvd
CVE-2025-20780HIGHCVSS 7.8vMT6739vMT6761+43 more2026-01-06
CVE-2025-20780 [HIGH] CWE-416 CVE-2025-20780: In display, there is a possible memory corruption due to use after free. This could lead to local es
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184061; Issue ID: MSV-4712.
cvelistv5nvd
CVE-2025-20793MEDIUMCVSS 6.5vMT2735vMT2737+47 more2026-01-06
CVE-2025-20793 [MEDIUM] CWE-476 CVE-2025-20793: In Modem, there is a possible system crash due to incorrect error handling. This could lead to remot
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01430930; Issue ID: MSV-4836.
cvelistv5nvd
CVE-2025-20787MEDIUMCVSS 6.7vMT2718vMT6739+28 more2026-01-06
CVE-2025-20787 [MEDIUM] CWE-416 CVE-2025-20787: In display, there is a possible memory corruption due to use after free. This could lead to local es
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10149879; Issue ID: MSV-4658.
cvelistv5nvd
CVE-2025-20784MEDIUMCVSS 6.7vMT6739vMT6761+43 more2026-01-06
CVE-2025-20784 [MEDIUM] CWE-457 CVE-2025-20784: In display, there is a possible memory corruption due to uninitialized data. This could lead to loca
In display, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182882; Issue ID: MSV-4683.
cvelistv5nvd