8.6

CVSS3.1

CVE-2023-37021 -

Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of serv…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.

7.3

CVSS3.1

CVE-2023-37013 -

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` routine to reach an unexpected network state and crash, leading …

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.

5.3

CVSS3.1

CVE-2023-37002 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `E-RAB Modification Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of servi…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:14 p.m.

5.7

CVSS3.1

CVE-2024-42012 -

GRAU DATA Blocky before 3.1 stores passwords encrypted rather than hashed. At the login screen, the user's password is compared to the user's decrypted cleartext password. An attacker with Windows admin or debugging rights can therefore steal the user's Blocky password and from there impersonate th…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: Feb. 4, 2025, 7:15 p.m.

8.6

CVSS3.1

CVE-2023-37018 -

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Capability Info Indication` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of servi…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.

8.6

CVSS3.1

CVE-2023-37019 -

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Supported TAs` field to repeatedly crash the MME, resulting in denial of service.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.

5.3

CVSS3.1

CVE-2023-37005 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of servi…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:14 p.m.

8.6

CVSS3.1

CVE-2023-37016 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of ser…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.

6.7

CVSS3.1

CVE-2025-22980 -

A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: June 18, 2025, 4:01 p.m.

5.7

CVSS3.1

CVE-2024-56914 -

D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 4:11 p.m.
Total resulsts: 343060
Page 6398 of 34,306
Β« previous page Β» next page
Filters