Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Open5gs MEDIUM 5.3
CVE-2024-24432

A reachable assertion in the ogs_kdf_hash_mme function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS pack…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs HIGH 8.6
CVE-2024-34235

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker …

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37015

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker …

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37016

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37017

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37018

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker …

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37019

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker …

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37020

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37021

Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs HIGH 8.6
CVE-2023-37023

Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its `MME_UE_S1AP_ID` field…

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37005

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37006

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37007

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37008

Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type c…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 6.3
CVE-2023-37009

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 6.3
CVE-2023-37010

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 6.3
CVE-2023-37011

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37012

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs HIGH 7.3
CVE-2023-37013

Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An …

Fix: after 2.6.4
Fix from $1,950 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37002

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37003

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Open5gs MEDIUM 5.3
CVE-2023-37004

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker m…

Fix: after 2.6.4
Fix from $1,600 2025-01-22
Magma HIGH 7.5
CVE-2024-24420

A reachable assertion in the decode_linked_ti_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows at…

Fix: after 1.8.0
Fix from $1,950 2025-01-21
Open5gs HIGH 7.5
CVE-2024-24427

A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packe…

Fix: after 2.6.4
Fix from $1,950 2025-01-21
Open5gs HIGH 7.5
CVE-2024-24428

A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP …

Fix: after 2.6.4
Fix from $1,950 2025-01-21
Magma HIGH 7.5
CVE-2023-37029

Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized…

Fix: after 1.8.0
Fix from $1,950 2025-01-21
Magma HIGH 7.5
CVE-2023-37024

A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486…

Fix: 1.9+
Fix from $1,950 2025-01-21
Linux Kernel MEDIUM 5.5
CVE-2024-57923

In the Linux kernel, the following vulnerability has been resolved: btrfs: zlib: fix avail_in bytes for s390 zlib HW compression path Since the inp…

Fix: 6.12.10+
Fix from $1,600 2025-01-19
Linux Kernel MEDIUM 5.5
CVE-2024-57924

In the Linux kernel, the following vulnerability has been resolved: fs: relax assertions on failure to encode file handles Encoding file handles is…

Fix: 6.1.151 / 6.6.74+
Fix from $1,600 2025-01-19
Linux Kernel MEDIUM 5.5
CVE-2025-21654

In the Linux kernel, the following vulnerability has been resolved: ovl: support encoding fid from inode with no alias Dmitry Safonov reported that…

Fix: 6.6.74 / 6.12.10+
Fix from $1,600 2025-01-19