Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2024-24417

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows ... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 14, 2025
  • 7.5

    HIGH
    CVE-2024-24416

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_access_point_name_ie function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers ... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 15, 2025
  • 7.8

    HIGH
    CVE-2023-40132

    In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
  • 5.5

    MEDIUM
    CVE-2023-40108

    In multiple locations, there is a possible way to access media content belonging to another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not nee... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
  • 6.5

    MEDIUM
    CVE-2023-37038

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Uplink NAS Transport` packet m... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 13, 2025
  • 6.5

    MEDIUM
    CVE-2023-37037

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missin... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 18, 2025
  • 6.5

    MEDIUM
    CVE-2023-37036

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Uplink NAS Transport` packet m... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 18, 2025
  • 6.5

    MEDIUM
    CVE-2023-37035

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missin... Read more

    Affected Products :
    • Published: Jan. 21, 2025
    • Modified: Jan. 22, 2025
  • 6.5

    MEDIUM
    CVE-2023-37034

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet mis... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 24, 2025
  • 6.5

    MEDIUM
    CVE-2023-37033

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet mis... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 20, 2025
  • 7.5

    HIGH
    CVE-2023-37032

    A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS pack... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 13, 2025
  • 6.5

    MEDIUM
    CVE-2023-37031

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `eNB Configuration Transfer` pa... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 19, 2025
  • 6.5

    MEDIUM
    CVE-2023-37030

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet mis... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 25, 2025
  • 7.5

    HIGH
    CVE-2023-37029

    Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may leverage this behavior to repeatedly crash the MME via either a c... Read more

    Affected Products : magma magma
    • Published: Jan. 21, 2025
    • Modified: Jan. 27, 2025
  • 6.5

    MEDIUM
    CVE-2023-37028

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modification Indication`... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 13, 2025
  • 6.5

    MEDIUM
    CVE-2023-37027

    Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modification Indication` p... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 18, 2025
  • 6.5

    MEDIUM
    CVE-2023-37026

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Release Response` packet... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Jan. 23, 2025
  • 6.5

    MEDIUM
    CVE-2023-37025

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Reset` packet missing an expec... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Jan. 23, 2025
  • 7.5

    HIGH
    CVE-2023-37024

    A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet conta... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Jan. 23, 2025
  • 8.8

    HIGH
    CVE-2025-23196

    A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when defining alert scripts, where the script filename field is executed... Read more

    Affected Products : ambari
    • Published: Jan. 21, 2025
    • Modified: Jun. 09, 2025
Showing 20 of 291021 Results