Vulnerabilities (CVE)

Filtered by vendor Mediatek Subscribe
Filtered by product Software Development Kit
Total 71 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-20139 4 Google, Linuxfoundation, Mediatek and 1 more 14 Android, Yocto, Mt2737 and 11 more 2026-06-17 N/A 6.5 MEDIUM
In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001270; Issue ID: MSV-1600.
CVE-2024-20138 2 Google, Mediatek 11 Android, Mt3605, Mt6985 and 8 more 2026-06-17 N/A 7.5 HIGH
In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998291; Issue ID: MSV-1604.
CVE-2024-20103 2 Google, Mediatek 14 Android, Mt3605, Mt6985 and 11 more 2026-06-17 N/A 9.8 CRITICAL
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001358; Issue ID: MSV-1599.
CVE-2024-20101 2 Google, Mediatek 17 Android, Mt3605, Mt6985 and 14 more 2026-06-17 N/A 9.8 CRITICAL
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; Issue ID: MSV-1602.
CVE-2024-20100 2 Google, Mediatek 19 Android, Iot Yocto, Mt3605 and 16 more 2026-06-17 N/A 9.8 CRITICAL
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Issue ID: MSV-1603.
CVE-2024-20073 2 Mediatek, Openwrt 4 Mt6890, Mt7622, Software Development Kit and 1 more 2026-06-17 N/A 6.6 MEDIUM
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00367704; Issue ID: MSV-1411.
CVE-2024-20072 2 Mediatek, Openwrt 5 Mt6890, Mt6990, Mt7622 and 2 more 2026-06-17 N/A 6.6 MEDIUM
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364732; Issue ID: MSV-1332.
CVE-2024-20071 2 Mediatek, Openwrt 5 Mt6890, Mt6990, Mt7622 and 2 more 2026-06-17 N/A 4.4 MEDIUM
In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00364733; Issue ID: MSV-1331.
CVE-2024-20018 1 Mediatek 2 Mt7615, Software Development Kit 2026-06-17 N/A 9.8 CRITICAL
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00348479; Issue ID: MSV-1019.
CVE-2024-20017 2 Mediatek, Openwrt 8 Mt6890, Mt7622, Mt7915 and 5 more 2026-06-17 N/A 9.8 CRITICAL
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.
CVE-2023-32831 1 Mediatek 12 Mt6890, Mt7612, Mt7613 and 9 more 2026-06-17 N/A 5.5 MEDIUM
In wlan driver, there is a possible PIN crack due to use of insufficiently random values. This could lead to local information disclosure with no execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00325055; Issue ID: MSV-868.