Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-20609

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.

PUBLISHED
Vendor
Apple, Apple, Apple, Apple, Apple
Product
iOS and iPadOS, tvOS, visionOS, macOS, watchOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20608

This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Apple, Apple, Red Hat, Red Hat, Apple, Red Hat, Apple, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, macOS, visionOS, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 7, Safari, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, iOS and iPadOS, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Provider severity
HIGH, MEDIUM
Conflicts
3

CVE-2026-20607

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access protected user data.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20606

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to bypass certain Privacy preferences.

PUBLISHED
Vendor
Apple, Apple
Product
macOS, iOS and iPadOS
Provider severity
HIGH
Conflicts
2

CVE-2026-20605

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to crash a system process.

PUBLISHED
Vendor
Apple, Apple
Product
iOS and iPadOS, macOS
Provider severity
MEDIUM
Conflicts
2

CVE-2026-20603

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Tahoe 26.3. An app with root privileges may be able to access private information.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20602

The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to cause a denial-of-service.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
MEDIUM
Conflicts
1

CVE-2026-20601

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to monitor keystrokes without user permission.

PUBLISHED
Vendor
Apple
Product
macOS
Provider severity
LOW
Conflicts
1

CVE-2026-2060

A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /simpleblooddonor/editcampaignform.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

PUBLISHED
Vendor
code-projects
Product
Simple Blood Donor Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-2059

A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Medical Center Portal Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-2058

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Post Query Details Page. This manipulation of the argument gnamex causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affect

PUBLISHED
Vendor
mathurvishal
Product
CloudClassroom-PHP-Project
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-2057

A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown function of the file /login.php. The manipulation of the argument User results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
SourceCodester
Product
Medical Center Portal Management System
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-2056

A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /wan_connection_status.asp of the component DHCP Connection Status Handler. The manipulation leads to information disclosure. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link, D-Link
Product
DIR-605L, DIR-619L
Provider severity
MEDIUM
Conflicts
3

CVE-2026-2055

A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown function of the component DHCP Client Information Handler. Executing a manipulation can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link, D-Link
Product
DIR-619L, DIR-605L
Provider severity
MEDIUM
Conflicts
3

CVE-2026-2054

A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of the component Wifi Setting Handler. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Vendor
D-Link, D-Link
Product
DIR-605L, DIR-619L
Provider severity
MEDIUM
Conflicts
3

CVE-2026-2053

The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful exploitation allows an unauthenticated attacker to control the destination of server-initiated requests originating from the WSO2 API Manager. This direct control can enable unautho

PUBLISHED
Vendor
WSO2
Product
WSO2 API Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-2052

The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.2 via the Display Logic feature. This is due to the plugin using eval() on user-supplied Display Logic expressions with an insufficient blocklist/allowlist that can be bypassed using array_map with string concatenation, combined with a lack of authorization enforcement on the extended_widget_opts_block at

PUBLISHED
Vendor
Marketing Fire, LLC, marketingfire
Product
Widget Options - Extended, Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets
Provider severity
HIGH
Conflicts
1

CVE-2026-2050

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, GIMP
Product
Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, GIMP
Provider severity
HIGH
Conflicts
3

CVE-2026-20498

In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20497

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20496

In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20495

In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20494

In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20493

In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20492

In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20491

In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20490

In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2049

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of HDR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, GIMP
Product
Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 9, GIMP
Provider severity
HIGH
Conflicts
3

CVE-2026-20489

In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20488

In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20486

In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20485

In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20484

In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20483

In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
HIGH
Conflicts
0

CVE-2026-20482

In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20481

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20480

In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For MT2735, MT3737); Issue ID: MSV-7586.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2048

GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of XWD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an all

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, GIMP
Product
Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.6 Telecommunications Update Service, Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On, Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat Enterprise Linux 9.4 Extended Update Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 9.6 Extended Update Support, Red Hat Enterprise Linux 7, GIMP
Provider severity
HIGH
Conflicts
3

CVE-2026-20479

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071; Issue ID: MSV-7620.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
HIGH
Conflicts
0

CVE-2026-20478

In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20477

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID: MSV-7658.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20476

In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20475

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20474

In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20473

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20472

In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10991467; Issue ID: MSV-7764.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20471

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) / AUTO00851171 (Note: For MT2735, MT2737); Issue ID: MSV-7790.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-20470

In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2047

A flaw was found in GIMP. This heap-based buffer overflow vulnerability in the ICNS file parsing component allows a remote attacker to execute arbitrary code. Exploitation requires user interaction, where the target must open a specially crafted malicious file or visit a malicious page. This issue stems from insufficient validation of user-supplied data length before copying it to a buffer, leading to potential arbitrary code execution in the context of the current process.

PUBLISHED
Vendor
Red Hat, GIMP, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 6, GIMP, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7
Provider severity
HIGH
Conflicts
3

CVE-2026-20469

In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533.

PUBLISHED
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Provider severity
MEDIUM
Conflicts
0