Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2024-43771

    In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
  • 8.8

    HIGH
    CVE-2024-43770

    In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed fo... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
  • 7.8

    HIGH
    CVE-2024-43765

    In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
  • 6.5

    MEDIUM
    CVE-2024-43763

    In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error in the code. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed f... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
  • 8.8

    HIGH
    CVE-2024-43096

    In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for e... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
  • 7.8

    HIGH
    CVE-2024-43095

    In multiple locations, there is a possible way to obtain any system permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
  • 7.8

    HIGH
    CVE-2024-34730

    In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not nee... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
  • 6.5

    MEDIUM
    CVE-2024-24443

    An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDU Session Resource Setup Respo... Read more

    Affected Products :
    • Published: Jan. 21, 2025
    • Modified: Jan. 23, 2025
  • 7.5

    HIGH
    CVE-2024-24428

    A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.... Read more

    Affected Products : open5gs
    • Published: Jan. 21, 2025
    • Modified: Jan. 24, 2025
  • 7.5

    HIGH
    CVE-2024-24427

    A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.... Read more

    Affected Products : open5gs
    • Published: Jan. 21, 2025
    • Modified: Jan. 24, 2025
  • 7.5

    HIGH
    CVE-2024-24424

    A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.... Read more

    Affected Products :
    • Published: Jan. 21, 2025
    • Modified: Mar. 14, 2025
  • 7.5

    HIGH
    CVE-2024-24423

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_esm_message_container function at /nas/ies/EsmMessageContainer.cpp. This vulnerability allows att... Read more

    Affected Products : magma magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 18, 2025
  • 7.5

    HIGH
    CVE-2024-24422

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a stack overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows a... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 19, 2025
  • 9.8

    CRITICAL
    CVE-2024-24421

    A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted NAS packet.... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Jul. 03, 2025
  • 7.5

    HIGH
    CVE-2024-24420

    A reachable assertion in the decode_linked_ti_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Jul. 03, 2025
  • 7.5

    HIGH
    CVE-2024-24419

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_traffic_flow_template_packet_filter function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability al... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 18, 2025
  • 7.5

    HIGH
    CVE-2024-24418

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_pdn_address function at /nas/ies/PdnAddress.cpp. This vulnerability allows attackers to cause a D... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 24, 2025
  • 7.5

    HIGH
    CVE-2024-24417

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows ... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 14, 2025
  • 7.5

    HIGH
    CVE-2024-24416

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_access_point_name_ie function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers ... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 15, 2025
  • 7.8

    HIGH
    CVE-2023-40132

    In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
Showing 20 of 291058 Results