Mediatek
Mediatek Mt6993 Firmware: vulnerabilidades y CVE
Mediatek Mt6993 Firmware tiene 20 vulnerabilidades publicadas, 20 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses20
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-20503 | Media (5.3) | 0.19% | — | 7 sept 2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional… |
| CVE-2026-20502 | Alta (8.4) | 0.13% | — | 7 sept 2026 | In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… |
| CVE-2026-20501 | Alta (8.4) | 0.13% | — | 7 sept 2026 | In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… |
| CVE-2026-20500 | Media (5.5) | 0.09% | — | 7 sept 2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID:… |
| CVE-2026-20489 | Media (4.4) | 0.16% | — | 3 ago 2026 | In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not… |
| CVE-2026-20488 | Media (4.4) | 0.16% | — | 3 ago 2026 | In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is… |
| CVE-2026-20486 | Media (6.7) | 0.17% | — | 3 ago 2026 | In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is… |
| CVE-2026-20485 | Media (6) | 0.16% | — | 3 ago 2026 | In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not… |
| CVE-2026-20484 | Media (4.4) | 0.16% | — | 3 ago 2026 | In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is… |
| CVE-2026-20483 | Alta (7.7) | 0.17% | — | 3 ago 2026 | In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… |
| CVE-2026-20477 | Media (6) | 0.17% | — | 3 ago 2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not… |
| CVE-2026-20475 | Media (6) | 0.17% | — | 3 ago 2026 | In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not… |
| CVE-2026-20474 | Media (6) | 0.13% | — | 3 ago 2026 | In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not… |
| CVE-2026-20473 | Media (6) | 0.17% | — | 3 ago 2026 | In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed… |
| CVE-2026-20450 | Media (6.5) | 0.29% | — | 4 may 2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional… |
| CVE-2026-20449 | Media (6.5) | 0.22% | — | 4 may 2026 | In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional… |
| CVE-2026-20448 | Media (6.7) | 0.15% | — | 4 may 2026 | In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2026-20447 | Media (6.7) | 0.11% | — | 4 may 2026 | In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction… |
| CVE-2026-20432 | Alta (8) | 0.29% | — | 7 abr 2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no… |
| CVE-2026-20431 | Media (6.5) | 0.31% | — | 7 abr 2026 | In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.