CVE-2024-20078
CRITICALDescription
In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08737250; Issue ID: MSV-1452.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| android | |
| android | |
| android | |
| mediatek | mt6768 |
| mediatek | mt6779 |
| mediatek | mt8321 |
| mediatek | mt8385 |
| mediatek | mt8755 |
| mediatek | mt8765 |
| mediatek | mt8766 |
| mediatek | mt8768 |
| mediatek | mt8771 |
| mediatek | mt8775 |
| mediatek | mt8781 |
| mediatek | mt8786 |
| mediatek | mt8788 |
| mediatek | mt8789 |
| mediatek | mt8791t |
| mediatek | mt8792 |
| mediatek | mt8795t |
| mediatek | mt8796 |
| mediatek | mt8797 |
| mediatek | mt8798 |
References
Frequently Asked Questions
What is CVE-2024-20078? +
How severe is CVE-2024-20078? +
What products are affected by CVE-2024-20078? +
How do I check if I'm vulnerable to CVE-2024-20078? +
Related Vulnerabilities
A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. …
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We …
In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device …
A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as …
A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion …
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, …