Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-20055


In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.


Published

2024-04-01T03:15:08.640

Last Modified

2025-04-23T13:46:52.570

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application linuxfoundation yocto 4.0 Yes
Application mediatek iot_yocto 23.2 Yes
Operating System google android 12.0 Yes
Operating System google android 13.0 Yes
Hardware mediatek mt2713 - No
Hardware mediatek mt8168 - No
Hardware mediatek mt8173 - No
Hardware mediatek mt8175 - No
Hardware mediatek mt8188 - No
Hardware mediatek mt8195 - No
Hardware mediatek mt8365 - No
Hardware mediatek mt8370 - No
Hardware mediatek mt8390 - No
Hardware mediatek mt8395 - No
Hardware mediatek mt8673 - No
Hardware mediatek mt8696 - No
Hardware mediatek mt8781 - No
Hardware mediatek mt8795t - No
Hardware mediatek mt8798 - No
Hardware mediatek mt8871 - No

References