CVE-2024-20141
MEDIUMDescription
In V5 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291402; Issue ID: MSV-2073.
Is your site exposed to CVE-2024-20141?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| android | |
| android | |
| android | |
| android | |
| mediatek | mt6739 |
| mediatek | mt6761 |
| mediatek | mt6765 |
| mediatek | mt6768 |
| mediatek | mt6771 |
| mediatek | mt6779 |
| mediatek | mt6781 |
| mediatek | mt6785 |
| mediatek | mt6833 |
| mediatek | mt6853 |
| mediatek | mt6873 |
| mediatek | mt6877 |
| mediatek | mt6885 |
| mediatek | mt6893 |
| mediatek | mt8167 |
| mediatek | mt8167s |
| mediatek | mt8175 |
| mediatek | mt8185 |
| mediatek | mt8195 |
| mediatek | mt8321 |
| mediatek | mt8362a |
| mediatek | mt8365 |
| mediatek | mt8385 |
| mediatek | mt8395 |
| mediatek | mt8666 |
| mediatek | mt8667 |
| mediatek | mt8673 |
| mediatek | mt8675 |
| mediatek | mt8678 |
| mediatek | mt8765 |
| mediatek | mt8766 |
| mediatek | mt8768 |
| mediatek | mt8771 |
| mediatek | mt8775 |
| mediatek | mt8781 |
| mediatek | mt8786 |
| mediatek | mt8788 |
| mediatek | mt8789 |
| mediatek | mt8791t |
| mediatek | mt8795t |
| mediatek | mt8797 |
| mediatek | mt8798 |
| mediatek | mt8893 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-20141? +
How severe is CVE-2024-20141? +
What products are affected by CVE-2024-20141? +
How do I check if I'm vulnerable to CVE-2024-20141? +
Related Vulnerabilities
OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c …
llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address writing. …
remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memory …
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes a specially crafted …
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows …