7.5

CVSS3.1

CVE-2023-34398 -

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Some values of this table are serialized archive according boost library. The boost library contains a vulnerability/null pointer dereference.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 4:12 p.m.

7.5

CVSS3.1

CVE-2023-34400 -

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. In case of parsing file, service try to define header inside the file and convert it to null-terminated string. If character is missed, will return null pointer.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 4:12 p.m.

6.8

CVSS3.1

CVE-2024-37600 -

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible stack buffer overflow in the Service Broker service affects NTG 6 head units. To perform this attack, physical access to Ethernet pins of the head unit base board is needed. With a static IP address,…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 4:12 p.m.

4.9

CVSS3.1

CVE-2023-34403 -

Mercedes-Benz head-unit NTG6 has Ethernet pins on Base Board to connect module CSB. Attacker can connect to this pins and get access to internal network. A race condition can be acquired and attacker can spoof β€œUserData” with desirable file path and access it though backup on USB.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 4:12 p.m.

3.7

CVSS3.1

CVE-2023-34401 -

Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary UD2 codec. Due to missed size checks in the enapsulate file, attacker can achieve Out-of-Bound Read in heap memory.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 4:12 p.m.

4.6

CVSS3.1

CVE-2024-37603 -

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible type confusion exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB interface of the car is needed. With prepared data, an attacker can cause the Use…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 4:12 p.m.

4.6

CVSS3.1

CVE-2024-37602 -

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible NULL pointer dereference in the Apple Car Play function affects NTG 6 head units. To perform this attack, physical access to Ethernet pins of the head unit base board is needed. With a static IP addr…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: June 27, 2025, 4:12 p.m.

8

CVSS3.1

CVE-2025-22960 -

A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitters. Unauthenticated attackers can access exposed log files (/logs/debug/xteLog*), potentially revealing sensitive session-related information such as session IDs (sess_id) and auth…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2024-56908 -

In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file endpoint. By providing malicious input in the rel_id parameter, combined with improper input validation, the attacker can bypass restrictions and upload arbitrary files to directo…

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2024-57782 -

An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.

πŸ“… Published: Feb. 13, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6746 of 34,919
Β« previous page Β» next page
Filters