6.7

CVSS3.1

CVE-2023-28907 - A lack of access restrictions on internal memory regions

There is no memory isolation between CPU cores of the MIB3 infotainment. This fact allows an attacker with access to the main operating system to compromise the CPU core responsible for CAN message processing. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainmen…

πŸ“… Published: June 28, 2025, 3:36 p.m. πŸ”„ Last Modified: June 30, 2025, 8:15 p.m.

5.4

CVSS3.1

CVE-2023-28908 - Integer Overflow in Non-Fragmented Data Reception

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving non-fragmented HCI packets on a channel. The vulnerability was originally discovered in Skod…

πŸ“… Published: June 28, 2025, 3:35 p.m. πŸ”„ Last Modified: June 30, 2025, 8:15 p.m.

8

CVSS3.1

CVE-2023-28909 - Integer Overflow Leading to MTU Bypass

A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving fragmented HCI packets on a channel. An attacker can leverage this vulnerability to bypass the MTU c…

πŸ“… Published: June 28, 2025, 3:35 p.m. πŸ”„ Last Modified: June 30, 2025, 8:15 p.m.

8

CVSS3.1

CVE-2023-28910 - Disabled Abortion Flag

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. The issue results from the disabled abortion flag eventually leading to bypassing assertion functions. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3…

πŸ“… Published: June 28, 2025, 3:34 p.m. πŸ”„ Last Modified: June 30, 2025, 6:38 p.m.

6.5

CVSS3.1

CVE-2023-28911 - Arbitrary Channel Disconnection Resulting in Denial of Service

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment. The issue results from the lack of proper validation of user-supplied data, which can result in an arbitrary channel disconnection. An attacker can leverage this vulnerability to cause a denial-of-service attack for every c…

πŸ“… Published: June 28, 2025, 3:34 p.m. πŸ”„ Last Modified: June 30, 2025, 6:38 p.m.

5.7

CVSS3.1

CVE-2023-28912 - Cleartext Phonebook Information

The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access to the system to obtain vehicle owner's contact data. The vulnerability was originally discovered in Skoda Superb III car with MIB3 info…

πŸ“… Published: June 28, 2025, 3:33 p.m. πŸ”„ Last Modified: June 30, 2025, 6:38 p.m.

6.3

CVSS3.1

CVE-2023-29113 - A lack of access control in custom IPC mechanism

The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication mechanism, leaving attackers with presence in the system an ability to undermine access control restrictions implemented at the operating sy…

πŸ“… Published: June 28, 2025, 3:33 p.m. πŸ”„ Last Modified: June 30, 2025, 6:38 p.m.

4.8

CVSS4.0

CVE-2025-6818 - HDF5 H5Ochunk.c H5O__chunk_protect heap-based overflow

A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5O__chunk_protect of the file /src/H5Ochunk.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may…

πŸ“… Published: June 28, 2025, 3:31 p.m. πŸ”„ Last Modified: July 8, 2025, 2:45 p.m.

7.5

CVSS3.1

CVE-2025-1991 - IBM Informix Dynamic Server denial of service

IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an integer underflow when processing packets.

πŸ“… Published: June 28, 2025, 1:02 p.m. πŸ”„ Last Modified: Aug. 24, 2025, 11:40 a.m.

4.8

CVSS4.0

CVE-2025-6817 - HDF5 H5Centry.c H5C__load_entry resource consumption

A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C__load_entry of the file /src/H5Centry.c. The manipulation leads to resource consumption. The attack needs to be approached locally. The exploit has been disclosed to the public a…

πŸ“… Published: June 28, 2025, 11:31 a.m. πŸ”„ Last Modified: July 6, 2025, 10:16 p.m.
Total resulsts: 343944
Page 4324 of 34,395
Β« previous page Β» next page
Filters