Latest CVE Feed
-
7.5
HIGHCVE-2023-37029
Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may leverage this behavior to repeatedly crash the MME via either a c... Read more
- Published: Jan. 21, 2025
- Modified: Jan. 27, 2025
-
6.5
MEDIUMCVE-2023-37028
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modification Indication`... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 13, 2025
-
6.5
MEDIUMCVE-2023-37027
Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modification Indication` p... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 18, 2025
-
6.5
MEDIUMCVE-2023-37026
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Release Response` packet... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Jan. 23, 2025
-
6.5
MEDIUMCVE-2023-37025
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Reset` packet missing an expec... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Jan. 23, 2025
-
7.5
HIGHCVE-2023-37024
A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet conta... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Jan. 23, 2025
-
8.8
HIGHCVE-2025-23196
A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when defining alert scripts, where the script filename field is executed... Read more
Affected Products : ambari- Published: Jan. 21, 2025
- Modified: Jun. 09, 2025
-
7.5
HIGHCVE-2025-23195
An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerability occurs due to insecure parsing of XML input using the `DocumentBuilderFactory` class without disabl... Read more
Affected Products : ambari- Published: Jan. 21, 2025
- Modified: Jun. 09, 2025
-
8.8
HIGHCVE-2024-51941
A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injec... Read more
Affected Products : ambari- Published: Jan. 21, 2025
- Modified: Jun. 09, 2025
-
9.1
CRITICALCVE-2024-45479
SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.... Read more
Affected Products : ranger- Published: Jan. 21, 2025
- Modified: Jun. 10, 2025
-
4.8
MEDIUMCVE-2024-45478
Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue.... Read more
Affected Products : ranger- Published: Jan. 21, 2025
- Modified: Jun. 10, 2025
-
7.5
HIGHCVE-2024-24451
A stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 24, 2025
-
6.5
MEDIUMCVE-2024-24445
OpenAirInterface CN5G AMF (oai-cn5g-amf) <= 2.0.0 contains a null dereference in its handling of unsupported NGAP protocol messages which allows an attacker with network-adjacent access to the AMF to carry out denial of service. When a procedure code/pres... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Mar. 18, 2025
-
7.5
HIGHCVE-2024-24444
Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Feb. 10, 2025
-
7.5
HIGHCVE-2024-24442
A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP message.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 24, 2025
-
8.6
HIGHCVE-2023-50733
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of newer Lexmark devices.... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
-
9.8
CRITICALCVE-2023-27113
pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the organizationCode parameter at project.php.... Read more
Affected Products : pearprojectapi- Published: Jan. 21, 2025
- Modified: May. 30, 2025
-
9.8
CRITICALCVE-2023-27112
pearProjectApi v2.8.10 was discovered to contain a SQL injection vulnerability via the projectCode parameter at project.php.... Read more
Affected Products : pearprojectapi- Published: Jan. 21, 2025
- Modified: May. 30, 2025
-
7.3
HIGHCVE-2025-21571
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.24 and prior to 7.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the... Read more
Affected Products : vm_virtualbox- Published: Jan. 21, 2025
- Modified: Apr. 29, 2025
-
6.1
MEDIUMCVE-2025-21570
Vulnerability in the Oracle Life Sciences Argus Safety product of Oracle Health Sciences Applications (component: Login). The supported version that is affected is 8.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network acce... Read more
- Published: Jan. 21, 2025
- Modified: Apr. 29, 2025