Lucene search

K
cveMediaTekCVE-2024-20079
HistoryJul 01, 2024 - 5:15 a.m.

CVE-2024-20079

2024-07-0105:15:04
CWE-787
MediaTek
web.nvd.nist.gov
33
gnss service
out of bounds write
local privilege escalation
input validation
system execution privileges

AI Score

7.2

Confidence

High

EPSS

0

Percentile

9.1%

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08044040; Issue ID: MSV-1491.

Affected configurations

Vulners
Node
googleandroidRange<13.0
OR
googleandroidRange<14.0
OR
mediatekmt6761_firmware
OR
mediatekmt6765_firmware
OR
mediatekmt6768_firmware
OR
mediatekmt6781_firmware
OR
mediatekmt6785_firmware
OR
mediatekmt6789_firmware
OR
mediatekmt6833_firmware
OR
mediatekmt6853_firmware
OR
mediatekmt6853t_firmware
OR
mediatekmt6855_firmware
OR
mediatekmt6873_firmware
OR
mediatekmt6875_firmware
OR
mediatekmt6877_firmware
OR
mediatekmt6879_firmware
OR
mediatekmt6883_firmware
OR
mediatekmt6885_firmware
OR
mediatekmt6886_firmware
OR
mediatekmt6889_firmware
OR
mediatekmt6891_firmware
OR
mediatekmt6893_firmware
OR
mediatekmt6895_firmware
OR
mediatekmt6983_firmware
OR
mediatekmt6985_firmware
OR
mediatekmt6989_firmware
OR
mediatekmt8666_firmware
OR
mediatekmt8667_firmware
OR
mediatekmt8673_firmware
OR
mediatekmt8676_firmware
OR
mediatekmt8678_firmware
VendorProductVersionCPE
googleandroid*cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
mediatekmt6761_firmware*cpe:2.3:a:mediatek:mt6761_firmware:*:*:*:*:*:*:*:*
mediatekmt6765_firmware*cpe:2.3:a:mediatek:mt6765_firmware:*:*:*:*:*:*:*:*
mediatekmt6768_firmware*cpe:2.3:a:mediatek:mt6768_firmware:*:*:*:*:*:*:*:*
mediatekmt6781_firmware*cpe:2.3:a:mediatek:mt6781_firmware:*:*:*:*:*:*:*:*
mediatekmt6785_firmware*cpe:2.3:a:mediatek:mt6785_firmware:*:*:*:*:*:*:*:*
mediatekmt6789_firmware*cpe:2.3:a:mediatek:mt6789_firmware:*:*:*:*:*:*:*:*
mediatekmt6833_firmware*cpe:2.3:a:mediatek:mt6833_firmware:*:*:*:*:*:*:*:*
mediatekmt6853_firmware*cpe:2.3:a:mediatek:mt6853_firmware:*:*:*:*:*:*:*:*
mediatekmt6853t_firmware*cpe:2.3:a:mediatek:mt6853t_firmware:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 301

CNA Affected

[
  {
    "vendor": "MediaTek, Inc.",
    "product": "MT6761, MT6765, MT6768, MT6781, MT6785, MT6789, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6886, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT6989, MT8666, MT8667, MT8673, MT8676, MT8678",
    "versions": [
      {
        "version": "Android 13.0, 14.0",
        "status": "affected"
      }
    ]
  }
]

AI Score

7.2

Confidence

High

EPSS

0

Percentile

9.1%

Related for CVE-2024-20079