5.3

CVSS3.1

CVE-2023-37005 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `Initial Context Setup Failure` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of servi…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:14 p.m.

8.6

CVSS3.1

CVE-2023-37016 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `UE Context Modification Response` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of ser…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.

6.7

CVSS3.1

CVE-2025-22980 -

A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: June 18, 2025, 4:01 p.m.

5.7

CVSS3.1

CVE-2024-56914 -

D-Link DSL-3782 v1.01 is vulnerable to Buffer Overflow in /New_GUI/ParentalControl.asp.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 4:11 p.m.

5.4

CVSS3.1

CVE-2024-56923 -

Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious payload into the Name field of a subscription. Th…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 8:41 p.m.

8.6

CVSS3.1

CVE-2024-24429 -

A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:27 p.m.

8.6

CVSS3.1

CVE-2023-37017 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Global eNB ID` field to repeatedly crash the MME, resulting in denial of service.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.

6.3

CVSS3.1

CVE-2023-37011 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:13 p.m.

7.8

CVSS3.1

CVE-2024-55957 -

In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages have a local privilege escalation vulnerability due to improper access control permissions on Windows systems.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2023-37008 -

Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in decoded fields, leading to invalid parsing and freeing of memory. An attacker may use this to crash an MME or potentially execute code in …

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:14 p.m.
Total resulsts: 346574
Page 6750 of 34,658
Β« previous page Β» next page
Filters