Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2024-24428

    A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.... Read more

    Affected Products : open5gs
    • Published: Jan. 21, 2025
    • Modified: Jan. 24, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2024-24427

    A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.... Read more

    Affected Products : open5gs
    • Published: Jan. 21, 2025
    • Modified: Jan. 24, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2024-24424

    A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.... Read more

    Affected Products :
    • Published: Jan. 21, 2025
    • Modified: Mar. 14, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2024-24423

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_esm_message_container function at /nas/ies/EsmMessageContainer.cpp. This vulnerability allows att... Read more

    Affected Products : magma magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 18, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2024-24422

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a stack overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows a... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 19, 2025
    • Vuln Type: Denial of Service
  • 9.8

    CRITICAL
    CVE-2024-24421

    A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted NAS packet.... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Jul. 03, 2025
    • Vuln Type: Memory Corruption
  • 7.5

    HIGH
    CVE-2024-24420

    A reachable assertion in the decode_linked_ti_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Jul. 03, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2024-24419

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_traffic_flow_template_packet_filter function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability al... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 18, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2024-24418

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_pdn_address function at /nas/ies/PdnAddress.cpp. This vulnerability allows attackers to cause a D... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 24, 2025
    • Vuln Type: Memory Corruption
  • 7.5

    HIGH
    CVE-2024-24417

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows ... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 14, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2024-24416

    The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_access_point_name_ie function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers ... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 15, 2025
    • Vuln Type: Denial of Service
  • 7.8

    HIGH
    CVE-2023-40132

    In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
    • Vuln Type: Authorization
  • 5.5

    MEDIUM
    CVE-2023-40108

    In multiple locations, there is a possible way to access media content belonging to another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not nee... Read more

    Affected Products : android
    • Published: Jan. 21, 2025
    • Modified: Apr. 22, 2025
    • Vuln Type: Authorization
  • 6.5

    MEDIUM
    CVE-2023-37038

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Uplink NAS Transport` packet m... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 13, 2025
    • Vuln Type: Denial of Service
  • 6.5

    MEDIUM
    CVE-2023-37037

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missin... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 18, 2025
    • Vuln Type: Denial of Service
  • 6.5

    MEDIUM
    CVE-2023-37036

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Uplink NAS Transport` packet m... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 18, 2025
    • Vuln Type: Denial of Service
  • 6.5

    MEDIUM
    CVE-2023-37035

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missin... Read more

    Affected Products :
    • Published: Jan. 21, 2025
    • Modified: Jan. 22, 2025
    • Vuln Type: Denial of Service
  • 6.5

    MEDIUM
    CVE-2023-37034

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet mis... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 24, 2025
    • Vuln Type: Denial of Service
  • 6.5

    MEDIUM
    CVE-2023-37033

    A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet mis... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 20, 2025
    • Vuln Type: Denial of Service
  • 7.5

    HIGH
    CVE-2023-37032

    A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS pack... Read more

    Affected Products : magma
    • Published: Jan. 21, 2025
    • Modified: Mar. 13, 2025
    • Vuln Type: Memory Corruption
Showing 20 of 291170 Results