cbcvebase.

Mediatek Inc Mediatek Chipset vulnerabilities

91 known vulnerabilities affecting mediatek_inc/mediatek_chipset.

Total CVEs
91
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH25MEDIUM64

Vulnerabilities

Page 4 of 5
CVE-2025-20782P4MEDIUMCVSS 6.7vMT6739vMT6761+43 more2026-01-06
CVE-2025-20782 [MEDIUM] CWE-787 CVE-2025-20782: In display, there is a possible out of bounds write due to a missing bounds check. This could lead t In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182882; Issue ID: MSV-4685.
nvd
CVE-2026-20440P4MEDIUMCVSS 6.7vMT2718vMT6899+3 more2026-03-02
CVE-2026-20440 [MEDIUM] CWE-1285 CVE-2026-20440: In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431968; Issue ID: MSV-5824.
nvd
CVE-2026-20441P4MEDIUMCVSS 6.7vMT2718vMT6899+3 more2026-03-02
CVE-2026-20441 [MEDIUM] CWE-787 CVE-2026-20441: In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to lo In MAE, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10432500; Issue ID: MSV-5803.
nvd
CVE-2025-20783P4MEDIUMCVSS 6.7vMT6739vMT6761+43 more2026-01-06
CVE-2025-20783 [MEDIUM] CWE-787 CVE-2025-20783: In display, there is a possible out of bounds write due to a missing bounds check. This could lead t In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182882; Issue ID: MSV-4684.
nvd
CVE-2025-20760P4MEDIUMCVSS 6.5vMT2735vMT2737+46 more2026-01-06
CVE-2025-20760 [MEDIUM] CWE-617 CVE-2025-20760: In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This cou In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01676750; Issue ID: MSV-4653.
nvd
CVE-2025-20794P4MEDIUMCVSS 6.5vMT2735vMT2737+48 more2026-01-06
CVE-2025-20794 [MEDIUM] CWE-121 CVE-2025-20794: In Modem, there is a possible system crash due to improper input validation. This could lead to remo In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847.
nvd
CVE-2025-20761P4MEDIUMCVSS 6.5vMT2735vMT2737+53 more2026-01-06
CVE-2025-20761 [MEDIUM] CWE-754 CVE-2025-20761: In Modem, there is a possible system crash due to incorrect error handling. This could lead to remot In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01311265; Issue ID: MSV-4655.
nvd
CVE-2026-20403P4MEDIUMCVSS 6.5vMT2735vMT2737+40 more2026-02-02
CVE-2026-20403 [MEDIUM] CWE-787 CVE-2026-20403: In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689254 (Note: For N15 and NR16) / MOLY01689259
nvd
CVE-2026-20420P4MEDIUMCVSS 6.5vMT2735vMT2737+34 more2026-02-02
CVE-2026-20420 [MEDIUM] CWE-125 CVE-2026-20420: In Modem, there is a possible system crash due to incorrect error handling. This could lead to remot In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738313; Issue ID: MSV-5935.
nvd
CVE-2026-20422P4MEDIUMCVSS 6.5vMT2735vMT2737+51 more2026-02-02
CVE-2026-20422 [MEDIUM] CWE-617 CVE-2026-20422: In Modem, there is a possible system crash due to improper input validation. This could lead to remo In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00827332; Issue ID: MSV-5919.
nvd
CVE-2026-20405P4MEDIUMCVSS 6.5vMT2735vMT2737+50 more2026-02-02
CVE-2026-20405 [MEDIUM] CWE-617 CVE-2026-20405: In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01688495; Issue ID: MSV-4818.
nvd
CVE-2026-20406P4MEDIUMCVSS 6.5vMT2735vMT2737+50 more2026-02-02
CVE-2026-20406 [MEDIUM] CWE-770 CVE-2026-20406: In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote d In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01726634; Issue ID: MSV-5728.
nvd
CVE-2026-20421P4MEDIUMCVSS 6.5vMT2735vMT6833+13 more2026-02-02
CVE-2026-20421 [MEDIUM] CWE-125 CVE-2026-20421: In Modem, there is a possible system crash due to improper input validation. This could lead to remo In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738293; Issue ID: MSV-5922.
nvd
CVE-2026-20402P4MEDIUMCVSS 6.5vMT2735vMT6833+17 more2026-02-02
CVE-2026-20402 [MEDIUM] CWE-787 CVE-2026-20402: In Modem, there is a possible system crash due to improper input validation. This could lead to remo In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00693083; Issue ID: MSV-5928.
nvd
CVE-2026-20454P4MEDIUMCVSS 6.4vMT6739vMT6761+34 more2026-06-01
CVE-2026-20454 [MEDIUM] CWE-367 CVE-2026-20454: In geniezone, there is a possible out of bounds write due to a race condition. This could lead to lo In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786.
nvd
CVE-2026-20438P4MEDIUMCVSS 6.4vMT2718vMT6899+9 more2026-03-02
CVE-2026-20438 [MEDIUM] CWE-367 CVE-2026-20438: In MAE, there is a possible out of bounds write due to a race condition. This could lead to local es In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10431920; Issue ID: MSV-5835.
nvd
CVE-2026-20461P4MEDIUMCVSS 5.3vMT2737vMT6813+31 more2026-07-01
CVE-2026-20461 [MEDIUM] CWE-787 CVE-2026-20461: In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01267281 / MOLY01318201; Issue ID: MSV-64
nvd
CVE-2026-20460P4MEDIUMCVSS 5.3vMT2735vMT2737+65 more2026-07-01
CVE-2026-20460 [MEDIUM] CWE-288 CVE-2026-20460: In Modem, there is a possible information disclosure due to improper input validation. This could le In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01811421; Issue ID: MSV-6788.
nvd
CVE-2026-20417P4MEDIUMCVSS 5.3vMT6991vMT6993+1 more2026-02-02
CVE-2026-20417 [MEDIUM] CWE-787 CVE-2026-20417: In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to l In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10314946 / ALPS10340155; Issue ID: MSV-5154.
nvd
CVE-2026-20457P4MEDIUMCVSS 5.3vMT2735vMT2737+57 more2026-07-01
CVE-2026-20457 [MEDIUM] CWE-476 CVE-2026-20457: In Modem, there is a possible system crash due to improper input validation. This could lead to remo In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01826924; Issue ID: MSV-7301.
nvd