CVE tracker
369 subscribers
5.04K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-20481 - Geniezone Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20481
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20482 - Qualcomm WLAN STA Firmware Denial of Service Vulnerability

CVE ID :CVE-2026-20482
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20483 - Telephony Local Privilege Escalation

CVE ID :CVE-2026-20483
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20484 - TFA Information Disclosure Vulnerability

CVE ID :CVE-2026-20484
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20485 - HFRP Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20485
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20486 - Imgsensor Improper Error Handling Local Privilege Escalation

CVE ID :CVE-2026-20486
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20488 - MediaTek Display Information Disclosure Vulnerability

CVE ID :CVE-2026-20488
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20489 - MediaTek Display Integer Overflow Information Disclosure

CVE ID :CVE-2026-20489
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20490 - CCCI Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-20490
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20491 - MediaTek med Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20491
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20492 - MediaTek Audio HAL Denial of Service Vulnerability

CVE ID :CVE-2026-20492
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20493 - Wi-Fi Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20493
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20494 - MediaTek WiFi Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-20494
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20495 - Bluetooth Driver Permission Bypass

CVE ID :CVE-2026-20495
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20496 - Geniezone Out-of-Bounds Read Vulnerability

CVE ID :CVE-2026-20496
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20497 - Geniezone Out-of-Bounds Write Vulnerability

CVE ID :CVE-2026-20497
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-20498 - Geniezone Privilege Escalation Vulnerability

CVE ID :CVE-2026-20498
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58059 - Quadratic-time escaping when stringifying X.500 distinguished names

CVE ID :CVE-2026-58059
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58060 - HSS public-key level count unbounded, enabling huge allocation on verify

CVE ID :CVE-2026-58060
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58061 - CCM-family modes write plaintext to caller buffer before tag check

CVE ID :CVE-2026-58061
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-58062 - Stapled OCSP response accepted without binding to the checked certificate

CVE ID :CVE-2026-58062
Published : 3 Aug 2026, 3:16 a.m. | 43 minutes ago
Description :In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...