Latest CVE Feed
-
7.8
HIGHCVE-2023-40132
In setActualDefaultRingtoneUri of RingtoneManager.java, there is a possible way to bypass content providers read permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2023-40108
In multiple locations, there is a possible way to access media content belonging to another user due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not nee... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2023-37038
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Uplink NAS Transport` packet m... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-37037
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missin... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-37036
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Uplink NAS Transport` packet m... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-37035
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `S1Setup Request` packet missin... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 22, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-37034
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet mis... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 24, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-37033
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet mis... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 20, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2023-37032
A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS pack... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Memory Corruption
-
6.5
MEDIUMCVE-2023-37031
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `eNB Configuration Transfer` pa... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-37030
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Initial UE Message` packet mis... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 25, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2023-37029
Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may leverage this behavior to repeatedly crash the MME via either a c... Read more
- Published: Jan. 21, 2025
- Modified: Jan. 27, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-37028
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modification Indication`... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-37027
Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Modification Indication` p... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-37026
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `E-RAB Release Response` packet... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Denial of Service
-
6.5
MEDIUMCVE-2023-37025
A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Reset` packet missing an expec... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2023-37024
A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet conta... Read more
Affected Products : magma- Published: Jan. 21, 2025
- Modified: Jan. 23, 2025
- Vuln Type: Denial of Service
-
8.8
HIGHCVE-2025-23196
A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when defining alert scripts, where the script filename field is executed... Read more
Affected Products : ambari- Published: Jan. 21, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-23195
An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerability occurs due to insecure parsing of XML input using the `DocumentBuilderFactory` class without disabl... Read more
Affected Products : ambari- Published: Jan. 21, 2025
- Modified: Jun. 09, 2025
- Vuln Type: XML External Entity
-
8.8
HIGHCVE-2024-51941
A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injec... Read more
Affected Products : ambari- Published: Jan. 21, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection