Latest CVE Feed
-
7.5
HIGHCVE-2023-37014
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Release Request` message missing a required `MME_UE_S1AP_ID` field to repeatedly cr... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
7.3
HIGHCVE-2023-37013
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` routine to reach an ... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
5.3
MEDIUMCVE-2023-37012
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial UE Message` message missing a required `PLMN Identity` field to repeatedly crash the M... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
6.3
MEDIUMCVE-2023-37011
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MM... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
6.3
MEDIUMCVE-2023-37010
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `eNB Status Transfer` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
6.3
MEDIUMCVE-2023-37009
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Notification` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash th... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
5.3
MEDIUMCVE-2023-37008
Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in decoded fields, leading to invalid parsing and freeing of memory. An attacker may use this to ... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
5.3
MEDIUMCVE-2023-37007
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Cancel` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME,... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
5.3
MEDIUMCVE-2023-37006
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Request Ack` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
5.3
MEDIUMCVE-2023-37005
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
5.3
MEDIUMCVE-2023-37004
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Response` message missing a required `MME_UE_S1AP_ID` field to repeatedl... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
5.3
MEDIUMCVE-2023-37003
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `E-RAB Setup Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash th... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
5.3
MEDIUMCVE-2023-37002
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `E-RAB Modification Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly... Read more
Affected Products : open5gs- Published: Jan. 22, 2025
- Modified: Apr. 22, 2025
-
8.9
HIGHCVE-2023-36998
The NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based buffer overflow vulnerability in the Emergency Number List decoding method. An attacker may send a NAS message containing an oversized Emergency Num... Read more
Affected Products :- Published: Jan. 22, 2025
- Modified: Feb. 06, 2025
-
7.5
HIGHCVE-2025-0395
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page siz... Read more
Affected Products : glibc- Published: Jan. 22, 2025
- Modified: Apr. 30, 2025
-
7.3
HIGHCVE-2024-13499
The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_do_shortcode() function in all versions up to, and including, 7.2.1. This... Read more
Affected Products : gamipress- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
-
7.5
HIGHCVE-2024-13496
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient esca... Read more
Affected Products : gamipress- Published: Jan. 22, 2025
- Modified: Mar. 24, 2025
-
7.3
HIGHCVE-2024-13495
The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via the gamipress_ajax_get_logs() function in all versions up to, and including, 7.2.1.... Read more
Affected Products : gamipress- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2024-13447
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hotel_booking_load_order_user AJAX action in all versions up to, and including, 2.1.6. This makes it possible for authenticated... Read more
Affected Products : wp_hotel_booking- Published: Jan. 22, 2025
- Modified: Jan. 24, 2025
-
6.1
MEDIUMCVE-2022-23439
A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before versio... Read more
Affected Products : fortimanager fortios fortiwlc fortimail fortiadc fortiproxy fortitester fortivoice fortiauthenticator fortiddos +9 more products- Published: Jan. 22, 2025
- Modified: Feb. 12, 2025