VDB

CVE-2024-20116

CVE-2024-20116 PUBLISHED CVSS 4.400000095367432 MEDIUM

In cmdq, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09057438; Issue ID: MSV-1696.

EPSS 0.08% · 0.3th percentile

Risk Scores

CVSS 3.1
4.400000095367432
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.08%
0.3th percentile

Affected Products

VendorProductVersions
mediatekmt87880
mediatekmt87650
mediatekmt87660
mediatekmt87970
mediatekmt67790
mediatekmt67650
mediatekmt87680
mediatekmt67850
mediatekmt87980
mediatekmt87810
mediatekmt67890
mediatekmt87860
MediaTek, Inc.MT6765, MT6768, MT6779, MT6781, MT6785, MT6789, MT8765, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8795T, MT8797, MT8798Android 12.0
googleandroid12.0
mediatekmt87710
mediatekmt8795t0
mediatekmt67680
mediatekmt87890
mediatekmt67810
mediatekmt8791t0

Timeline

  • Dec 2, 2024 EPSS Score
  • Dec 2, 2024 CVE Published
  • Dec 2, 2024 PoC Published
  • Dec 2, 2024 PoC Published
  • Dec 2, 2024 CVE Updated
  • Dec 19, 2024 EPSS Score
  • Jan 5, 2025 EPSS Score
  • Jan 22, 2025 EPSS Score
  • Feb 7, 2025 Coalition ESS Score
  • Feb 8, 2025 EPSS Score
  • Feb 25, 2025 EPSS Score
  • Mar 14, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›