VDB
CVE-2024-20107
CVE-2024-20107
PUBLISHED
CVSS 6.900000095367432 MEDIUM
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09124360; Issue ID: MSV-1823.
EPSS 0.10% · 1.1th percentile
Risk Scores
CVSS 4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.10%
1.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| linuxfoundation | yocto | 4.0, 4.0 |
| openwrt | openwrt | 19.07.0, 19.07.0, 21.02.0 |
| MediaTek, Inc. | MT6781, MT6789, MT6835, MT6855, MT6878, MT6879, MT6880, MT6886, MT6890, MT6895, MT6897, MT6980, MT6983, MT6985, MT6989, MT6990, MT8188, MT8370, MT8390, MT8676 | Android 12.0, 13.0, 14.0, 15.0 / openWRT 19.07, 21.02, 23.05 / Yocto 4.0 / RDK-B 22Q3, 24Q1, Android 12.0, 13.0, 14.0, 15.0 / openWRT 19.07, 21.02, 23.05 / Yocto 4.0 / RDK-B 22Q3, 24Q1 |
| android | 12.0, 13.0, 15.0 | |
| rdkcentral | rdk-b | 2022q3, 2024q1, * |
Timeline
- Nov 4, 2024 EPSS Score
- Nov 4, 2024 CVE Published
- Nov 4, 2024 PoC Published
- Nov 4, 2024 CVE Updated
- Nov 6, 2024 Coalition ESS Score
- Nov 22, 2024 EPSS Score
- Dec 11, 2024 EPSS Score
- Dec 29, 2024 EPSS Score
- Jan 16, 2025 EPSS Score
- Jan 23, 2025 Coalition ESS Score
- Feb 3, 2025 EPSS Score
- Feb 21, 2025 EPSS Score