Vulnerability index

Browse CVEs

414 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Magma HIGH 7.5
CVE-2023-37029

Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized…

Fix: after 1.8.0
Fix from $1,950 2025-01-21
Magma HIGH 7.5
CVE-2023-37032

A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fe…

Fix: after 1.8.0
Fix from $1,950 2025-01-21
Magma MEDIUM 6.5
CVE-2023-37028

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90…

Fix: 1.9+
Fix from $1,600 2025-01-21
Magma MEDIUM 6.5
CVE-2023-37030

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90…

Fix: after 1.8.0
Fix from $1,600 2025-01-21
Magma MEDIUM 6.5
CVE-2023-37031

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90…

Fix: after 1.8.0
Fix from $1,600 2025-01-21
Magma MEDIUM 6.5
CVE-2023-37033

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90…

Fix: after 1.8.0
Fix from $1,600 2025-01-21
Magma MEDIUM 6.5
CVE-2023-37034

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90…

Fix: after 1.8.0
Fix from $1,600 2025-01-21
Magma MEDIUM 6.5
CVE-2023-37036

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90…

Fix: after 1.8.0
Fix from $1,600 2025-01-21
Magma HIGH 7.5
CVE-2023-37024

A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486…

Fix: 1.9+
Fix from $1,950 2025-01-21
Magma MEDIUM 6.5
CVE-2023-37025

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90…

Fix: 1.9+
Fix from $1,600 2025-01-21
Magma MEDIUM 6.5
CVE-2023-37026

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90…

Fix: 1.9+
Fix from $1,600 2025-01-21
Magma MEDIUM 6.5
CVE-2023-37027

Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fe…

Fix: 1.9+
Fix from $1,600 2025-01-21
Yocto CRITICAL 9.8
CVE-2024-20148

In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code executio…

Fix: after 2.4
Fix from $2,300 2025-01-06
Yocto HIGH 7.5
CVE-2024-20153

In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with n…

Fix: after 3.5
Fix from $1,950 2025-01-06
Yocto HIGH 8.1
CVE-2024-20146

In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code exec…

Fix: after 2.5
Fix from $1,950 2025-01-06
Yocto MEDIUM 6.7
CVE-2024-20140

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious acto…

Mitigation only
Fix from $1,600 2025-01-06
Yocto MEDIUM 6.6
CVE-2024-20143

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has…

Mitigation only
Fix from $1,600 2025-01-06
Yocto MEDIUM 6.6
CVE-2024-20144

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has…

Mitigation only
Fix from $1,600 2025-01-06
Yocto MEDIUM 6.6
CVE-2024-20145

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has…

Mitigation only
Fix from $1,600 2025-01-06
Yocto MEDIUM 6.5
CVE-2024-20139

In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of se…

Fix: after 3.3
Fix from $1,600 2024-12-02
Harbor HIGH 7.7
CVE-2022-31670

Harbor fails to validate the user permissions when updating tag retention policies.  By sending a request to update a tag retention policy with an i…

Fix: 1.10.13 / 2.4.3+
Fix from $1,950 2024-11-14
Harbor HIGH 7.4
CVE-2022-31671

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request t…

Fix: 2.4.3 / 2.5.2+
Fix from $1,950 2024-11-14
Harbor HIGH 7.7
CVE-2022-31668

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that…

Fix: 2.4.3 / 2.5.2+
Fix from $1,950 2024-11-14
Harbor HIGH 7.7
CVE-2022-31669

Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy wit…

Fix: 2.4.3 / 2.5.2+
Fix from $1,950 2024-11-14
Harbor MEDIUM 6.4
CVE-2022-31667

Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access…

Fix: 2.4.3 / 2.5.2+
Fix from $1,600 2024-11-14
Harbor MEDIUM 5.4
CVE-2022-31666

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of ot…

Fix: 2.4.3 / 2.5.2+
Fix from $1,600 2024-11-14
Yocto MEDIUM 6.2
CVE-2024-20107

In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execu…

Mitigation only
Fix from $1,600 2024-11-04
Yocto HIGH 8.4
CVE-2024-20104

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional exe…

Mitigation only
Fix from $1,950 2024-11-04
Pytorch CRITICAL 9.8
CVE-2024-48063

In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch…

Fix: after 2.4.1
Fix from $2,300 2024-10-29
Zowe Api Mediation Layer MEDIUM 5.3
CVE-2024-9798

The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.

Fix: 1.28.8 / 2.18.0+
Fix from $1,600 2024-10-10