Mediatek
Mediatek IOT Yocto: vulnerabilidades y CVE
Mediatek IOT Yocto tiene 24 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-20721 | Alta (7.8) | 0.09% | — | 14 oct 2025 | In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is… |
| CVE-2024-20100 | Crítica (9.8) | 0.33% | — | 7 oct 2024 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for… |
| CVE-2024-20055 | Media (6.3) | 0.08% | — | 1 abr 2024 | In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation… |
| CVE-2023-32829 | Media (6.7) | 0.09% | — | 2 oct 2023 | In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.… |
| CVE-2023-32828 | Media (6.7) | 0.10% | — | 2 oct 2023 | In vpu, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.… |
| CVE-2023-32820 | Alta (7.5) | 0.51% | — | 2 oct 2023 | In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for… |
| CVE-2023-32811 | Media (6.7) | 0.10% | — | 4 sept 2023 | In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not… |
| CVE-2023-32807 | Media (4.4) | 0.10% | — | 4 sept 2023 | In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for… |
| CVE-2023-32806 | Media (6.7) | 0.10% | — | 4 sept 2023 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for… |
| CVE-2023-20850 | Media (6.5) | 0.10% | — | 4 sept 2023 | In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20849 | Media (6.5) | 0.11% | — | 4 sept 2023 | In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20848 | Media (6.5) | 0.10% | — | 4 sept 2023 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20847 | Media (4.2) | 0.10% | — | 4 sept 2023 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20846 | Media (4.2) | 0.10% | — | 4 sept 2023 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20845 | Media (4.2) | 0.10% | — | 4 sept 2023 | In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20844 | Media (4.2) | 0.10% | — | 4 sept 2023 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20843 | Media (4.2) | 0.10% | — | 4 sept 2023 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20842 | Media (6.5) | 0.10% | — | 4 sept 2023 | In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20841 | Media (6.5) | 0.10% | — | 4 sept 2023 | In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20840 | Media (6.5) | 0.10% | — | 4 sept 2023 | In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20839 | Media (4.2) | 0.10% | — | 4 sept 2023 | In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20835 | Media (6.4) | 0.07% | — | 4 sept 2023 | In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID:… |
| CVE-2023-20812 | Media (4.4) | 0.09% | — | 7 ago 2023 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for… |
| CVE-2023-20673 | Media (6.7) | 0.10% | — | 15 may 2023 | In vcu, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID:… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.