CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2023-37007

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Cancel` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    5.3
    Medium

    CVE-2023-37008

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in decoded fields, leading to invalid parsing and freeing of memory. An attacker may use this to crash an MME or potentially execute code in certain circumstances.

    Published: 22 Jan 2025
    6.3
    Medium

    CVE-2023-37009

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Notification` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    6.3
    Medium

    CVE-2023-37011

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    5.3
    Medium

    CVE-2023-37012

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` message missing a required `PLMN Identity` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    7.3
    High

    CVE-2023-37013

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` routine to reach an unexpected network state and crash, leading to denial of service.

    Published: 22 Jan 2025
    7.5
    High

    CVE-2023-37014

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    8.6
    High

    CVE-2023-37015

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Path Switch Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    8.6
    High

    CVE-2023-37016

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    8.6
    High

    CVE-2023-37018

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Capability Info Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    8.6
    High

    CVE-2023-37019

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Supported TAs` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    8.6
    High

    CVE-2023-37020

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Complete` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    8.6
    High

    CVE-2023-37021

    Last Modified: 22 Apr 2025

    Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    7.5
    High

    CVE-2023-37022

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet containing an invalid `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

    Published: 22 Jan 2025
    8.6
    High

    CVE-2023-37023

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field causes Open5gs to crash; an attacker may repeatedly send such packets to cause denial of service.

    Published: 22 Jan 2025
    8.6
    High

    CVE-2024-24429

    Last Modified: 22 Apr 2025

    A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

    Published: 22 Jan 2025
    5.3
    Medium

    CVE-2024-24432

    Last Modified: 22 Apr 2025

    A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

    Published: 22 Jan 2025
    8.6
    High

    CVE-2024-34235

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` missing a required `NAS_PDU` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    7.8
    High

    CVE-2024-55957

    Last Modified: 15 Apr 2026

    In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages have a local privilege escalation vulnerability due to improper access control permissions on Windows systems.

    Published: 22 Jan 2025
    5.7
    Medium

    CVE-2024-56914

    Last Modified: 21 May 2025

    D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.

    Published: 22 Jan 2025
    7.3
    High

    CVE-2024-56924

    Last Modified: 4 Aug 2025

    A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript on the admin page (pages_account), potentially leading to unauthorized actions such as changing account settings or stealing sensitive user information. This vulnerability occurs due to improper validation of user requests, which enables attackers to exploit the system by tricking the admin user into executing malicious scripts.

    Published: 22 Jan 2025
    6.3
    Medium

    CVE-2023-37010

    Last Modified: 22 Apr 2025

    Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `eNB Status Transfer` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

    Published: 22 Jan 2025
    9.8
    Critical

    CVE-2024-13091

    Last Modified: 8 Apr 2026

    The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'qcld_wpcfb_file_upload' function in all versions up to, and including, 13.5.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit requires thee ChatBot Conversational Forms plugin and the Conversational Form Builder Pro addon plugin.

    Published: 21 Jan 2025
    8.8
    High

    CVE-2024-49749

    Last Modified: 26 Feb 2026

    In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    9.8
    Critical

    CVE-2024-49748

    Last Modified: 22 Apr 2025

    In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    9.8
    Critical

    CVE-2024-49747

    Last Modified: 22 Apr 2025

    In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    7.8
    High

    CVE-2024-49745

    Last Modified: 22 Apr 2025

    In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    7.8
    High

    CVE-2024-49744

    Last Modified: 22 Apr 2025

    In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mitigation due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 21 Jan 2025
    7.8
    High

    CVE-2024-49742

    Last Modified: 22 Apr 2025

    In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification access in Settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 21 Jan 2025
    7.8
    High

    CVE-2024-49738

    Last Modified: 22 Apr 2025

    In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    7.8
    High

    CVE-2024-49737

    Last Modified: 22 Apr 2025

    In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities as the system UID due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    5.5
    Medium

    CVE-2024-49736

    Last Modified: 22 Apr 2025

    In onClick of MainClear.java, there is a possible way to trigger factory reset without explicit user consent due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    7.8
    High

    CVE-2024-49735

    Last Modified: 22 Apr 2025

    In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    7.5
    High

    CVE-2024-49734

    Last Modified: 22 Apr 2025

    In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a device has connected to through a VPN due to side channel information disclosure. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    5.5
    Medium

    CVE-2024-49733

    Last Modified: 22 Apr 2025

    In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    7.8
    High

    CVE-2024-49732

    Last Modified: 22 Apr 2025

    In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    7
    High

    CVE-2024-49724

    Last Modified: 22 Apr 2025

    In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected activities due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 21 Jan 2025
    8.8
    High

    CVE-2024-43771

    Last Modified: 22 Apr 2025

    In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    8.8
    High

    CVE-2024-43770

    Last Modified: 22 Apr 2025

    In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    7.8
    High

    CVE-2024-43765

    Last Modified: 26 Feb 2026

    In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

    Published: 21 Jan 2025
    6.5
    Medium

    CVE-2024-43763

    Last Modified: 22 Apr 2025

    In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    8.8
    High

    CVE-2024-43096

    Last Modified: 22 Apr 2025

    In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    7.8
    High

    CVE-2024-43095

    Last Modified: 26 Feb 2026

    In multiple locations, there is a possible way to obtain any system permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 21 Jan 2025
    7.8
    High

    CVE-2024-34730

    Last Modified: 26 Feb 2026

    In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    7.8
    High

    CVE-2023-40132

    Last Modified: 17 Jun 2026

    In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 21 Jan 2025
    5.5
    Medium

    CVE-2023-40108

    Last Modified: 17 Jun 2026

    In multiple locations, there is a possible way to access media content belonging to another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 21 Jan 2025
    8.6
    High

    CVE-2023-50733

    Last Modified: 15 Apr 2026

    A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of newer Lexmark devices.

    Published: 21 Jan 2025
    9.1
    Critical

    CVE-2024-45479

    Last Modified: 10 Jun 2025

    SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.

    Published: 21 Jan 2025
    4.8
    Medium

    CVE-2024-45478

    Last Modified: 10 Jun 2025

    Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.

    Published: 21 Jan 2025
    8.8
    High

    CVE-2024-51941

    Last Modified: 2 Oct 2025

    A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injected into the alert script execution path. An attacker with authenticated access can exploit this vulnerability to execute arbitrary commands on the server. The issue has been fixed in the latest versions of Ambari.

    Published: 21 Jan 2025