CVE Catalog
Browse the latest Common Vulnerabilities and Exposures (CVEs) with CVSS scores, affected products, and next-gen risk scores.
Magma Linked TI IE NAS Packet Vulnerability Allowing Denial-of-Service
A denial-of-service vulnerability has been identified in Magma versions through 1.8.0. The issue arises in the 'decode_linked_ti_ie' function, where a reachable assertion can be triggered by sending a crafted NAS packet that includes a malformed Linked TI Information Element. This vulnerability can cause the Access and Mobility Management Function (AMF) to crash, disrupting cellular services.
The Linux Foundation Magma Buffer Overflow Vulnerability in Traffic Flow Template Packet Filtering Allowing Denial-of-Service
A buffer overflow vulnerability has been identified in The Linux Foundation Magma version 1.8.0 and prior, within the 'decode_traffic_flow_template_packet_filter' function of the 3gpp_24.008_sm_ies.c file. This vulnerability allows attackers to cause a denial-of-service by sending a crafted NAS packet, disrupting cellular network services.
The Linux Foundation Magma Buffer Overflow Vulnerability in PDN Address Decoding Function Allows Denial-of-Service
A buffer overflow vulnerability has been identified in The Linux Foundation Magma version 1.8.0 and prior. The issue arises in the 'decode_pdn_address' function within the PDNAddress.cpp file, where improper handling of crafted NAS packets can lead to a denial-of-service condition. This vulnerability is present in the 5G core implementation of Magma.
The Linux Foundation Magma Buffer Overflow Vulnerability in Protocol Configuration Options Decoding
A buffer overflow vulnerability has been identified in The Linux Foundation Magma version 1.8.0 and earlier. This issue arises in the 'decode_protocol_configuration_options' function within the file '3gpp_24.008_sm_ies.c'. The vulnerability allows attackers to cause a denial-of-service (DoS) by sending a crafted NAS packet, leading to a service disruption in cellular communications.
The Linux Foundation Magma Buffer Overflow Vulnerability in Access Point Name Decoding Allows Denial-of-Service
A buffer overflow vulnerability has been identified in The Linux Foundation Magma version 1.8.0 and prior. This issue arises in the 'decode_access_point_name_ie' function within the '3gpp/3gpp_24.008_sm_ies.c' file. The vulnerability allows attackers to cause a denial-of-service by sending a crafted NAS packet, exploiting the buffer overflow during the decoding process.
Android Ringtone Manager Content Provider Permission Bypass Vulnerability Allowing Privilege Escalation
A vulnerability in the RingtoneManager's setActualDefaultRingtoneUri method allows for a bypass of content provider read permissions, due to a lack of proper permission checks. This issue could lead to local privilege escalation, requiring user interaction for exploitation.
Android Media Framework Missing Permission Check Vulnerability Allowing Unauthorized Media Access
A vulnerability exists in the Android media framework that allows unauthorized access to another user's media content. This issue arises from a missing permission check, which could lead to local information disclosure without requiring additional execution privileges or user interaction. The vulnerability affects multiple Android versions and components.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) component of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP 'Uplink NAS Transport' packet that omits the required 'MME_UE_S1AP_ID' field. The issue has been fixed in Magma version 1.9.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability via S1AP S1Setup Request
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP S1Setup Request packet that omits the expected Supported TAs field. The issue has been fixed in Magma version 1.9.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) component of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP 'Uplink NAS Transport' packet that lacks the required 'ENB_UE_S1AP_ID' field.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability via Malformed S1AP S1Setup Request Packet
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP S1Setup Request packet that omits the required Global eNB ID field. The issue has been fixed in Magma version 1.9.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability via Malformed S1AP Initial UE Message
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP Initial UE Message packet that omits the required TAI field. The issue has been addressed in Magma version 1.9.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability via Malformed S1AP Initial UE Message
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP Initial UE Message packet that omits the required EUTRAN_CGI field.
Magma Mobile Management Entity Stack-Based Buffer Overflow Vulnerability Allowing Denial-of-Service
A stack-based buffer overflow vulnerability has been identified in the Mobile Management Entity (MME) of Magma, affecting versions through 1.8.0. This vulnerability allows remote attackers to crash the MME by sending a NAS packet with an oversized 'Emergency Number List' Information Element, using an unauthenticated cellphone. The issue has been fixed in Magma version 1.9.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability via S1AP eNB Configuration Transfer Packet
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP 'eNB Configuration Transfer' packet that omits the required 'Target eNB ID' field. The issue has been fixed in Magma version 1.9.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability via Malformed S1AP Initial UE Message
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP Initial UE Message packet that lacks the required eNB_UE_S1AP_ID field.
Magma Oversized NAS Packet Vulnerability Leading to Assertion-Based Denial-of-Service
A denial-of-service vulnerability has been identified in Magma versions through 1.8.0. When the MME receives an oversized NAS packet, it triggers an assertion failure, causing a crash. This issue can be exploited by an attacker using a compromised base station or an unauthenticated cellphone within range of the base station, leading to a persistent disruption of cellular services.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability via S1AP E-RAB Modification Indication Packet
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP E-RAB Modification Indication packet that omits the required eNB_UE_S1AP_ID field. The issue has been addressed in Magma version 1.9.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability via S1AP E-RAB Modification Indication Packet
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP 'E-RAB Modification Indication' packet that omits the required 'eNB_UE_S1AP_ID' field. The issue has been fixed in Magma version 1.9.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) component of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP 'E-RAB Release Response' packet that lacks the required 'MME_UE_S1AP_ID' field. The issue has been fixed in Magma version 1.9.
Magma Mobile Management Entity Null Pointer Dereference Vulnerability via Malformed S1AP Reset Packet
A null pointer dereference vulnerability has been identified in the Mobile Management Entity (MME) component of Magma versions through 1.8.0. This vulnerability allows network-adjacent attackers to crash the MME by sending an S1AP Reset packet that omits the required ResetType field. The issue arises because the MME's S1AP handling routines do not properly validate the presence of this field before attempting to access it, leading to a crash when the field is missing.
Magma Mobile Management Entity Reachable Assertion Vulnerability Allowing Denial-of-Service
A reachable assertion vulnerability has been identified in the Mobile Management Entity (MME) of Magma, affecting versions through 1.8.0. This vulnerability allows remote attackers to crash the MME by sending a NAS packet that includes an 'Emergency Number List' Information Element. The issue arises from an incomplete parsing routine that fails to properly handle the emergency number data, leading to an assertion failure.
Apache Ambari Code Injection Vulnerability in Alert Definition Feature
A code injection vulnerability has been identified in the Apache Ambari Alert Definition feature, affecting versions prior to 2.7.9. This vulnerability allows authenticated users to inject and execute arbitrary shell commands. The issue arises when alert scripts are defined, as the script filename field is executed using 'sh -c'. An attacker with authenticated access can exploit this to execute malicious commands, leading to remote code execution on the server.
Apache Ambari and Oozie XML External Entity (XXE) Vulnerability
A XML External Entity (XXE) vulnerability has been identified in Apache Ambari versions prior to 2.7.9, specifically within the Oozie project. This vulnerability allows attackers to inject malicious XML entities, exploiting insecure XML parsing that uses the DocumentBuilderFactory class without disabling external entity resolution. As a result, attackers could read arbitrary files on the server or conduct server-side request forgery (SSRF) attacks.
Apache Ambari Remote Code Injection Vulnerability in Metrics and AMS Alerts
A remote code injection vulnerability has been identified in Apache Ambari versions through 2.7.8, specifically within the Ambari Metrics and AMS Alerts feature. This vulnerability allows authenticated users to inject and execute arbitrary code by exploiting the alert definitions process. Malicious input can be inserted into the execution path of alert scripts, enabling an attacker with authenticated access to execute commands on the server.
Apache Ranger SSRF Vulnerability in Edit Service Page
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Edit Service page of the Apache Ranger UI, specifically in version 2.4.0 prior to 2.5.0. This vulnerability allows users to manipulate requests sent to the server, potentially accessing internal resources or services that should be protected.
Apache Ranger Stored Cross-Site Scripting Vulnerability in Edit Service Page
A stored cross-site scripting vulnerability has been identified in the Edit Service page of the Apache Ranger UI, specifically in version 2.4.0 prior to 2.5.0. This vulnerability allows users to inject malicious scripts that are executed when other users access the affected page.
OpenAirInterface CN5G AMF Stack Overflow Vulnerability in SCTP Receiver Thread Component Allowing Denial-of-Service
A stack overflow vulnerability has been identified in the 'sctp_server::sctp_receiver_thread' component of OpenAirInterface CN5G AMF, in versions through 2.0.0. This vulnerability allows attackers to cause a denial-of-service (DoS) by repeatedly establishing SCTP connections with the N2 interface. The issue arises from missing bounds checks on file descriptors, which can lead to a buffer overflow when more than 1024 descriptors are open.
OpenAirInterface CN5G AMF Null Dereference Vulnerability in NGAP Message Handling Allowing Denial-of-Service
A null dereference vulnerability has been identified in OpenAirInterface CN5G AMF versions through 2.0.0. The issue arises in the application's handling of unsupported NGAP protocol messages. When an unsupported procedure code and presence field tuple is received, the application incorrectly indexes into a null function pointer, leading to a dereference. This vulnerability allows an attacker with network-adjacent access to the AMF to cause a denial-of-service condition.
OpenAirInterface CN5G AMF Improper File Descriptor Handling in Closed Connections Allowing Denial-of-Service
A denial-of-service vulnerability has been identified in OpenAirInterface CN5G AMF versions through 2.0.0. The issue arises from improper handling of file descriptors for closed SCTP connections, specifically on the N2 interface. This flaw allows attackers to exhaust server resources by repeatedly opening and closing connections, leading to resource exhaustion and potential service disruption.
OpenAirInterface CN5G AMF NULL Pointer Dereference Vulnerability in NGAP Message Handling
A NULL pointer dereference vulnerability has been identified in the OpenAirInterface CN5G Access and Mobility Management Function (AMF) versions through 2.0.0. The issue arises in the ngap_app::handle_receive function, where the application fails to properly handle unsupported NGAP protocol messages. This flaw allows attackers to send crafted NGAP messages that cause a denial-of-service condition by crashing the AMF.
Lexmark Devices Web Services SSRF Vulnerability
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services feature of certain Lexmark devices. This vulnerability allows an attacker to manipulate server-side requests, potentially leading to unauthorized access or actions on behalf of the server.
pearProjectApi SQL Injection Vulnerability in project.php
A SQL injection vulnerability has been identified in pearProjectApi version 2.8.10. The issue arises in the project.php file, specifically within the selfList method. The vulnerability is triggered by the organizationCode parameter, which is improperly sanitized before being used in a SQL query. This allows attackers to manipulate the SQL statement and execute arbitrary SQL commands, potentially leading to unauthorized data access.
pearProjectApi SQL Injection Vulnerability in project.php
A SQL injection vulnerability has been identified in pearProjectApi version 2.8.10. The issue arises in the project.php file, specifically within the getLogBySelfProject method. When the projectCode parameter is provided, it is directly inserted into the SQL query without proper sanitization, allowing attackers to manipulate the SQL statement and execute arbitrary SQL commands.
Oracle VM VirtualBox Core Vulnerability Allowing Privileged Data Manipulation and Partial Denial-of-Service
A vulnerability exists in Oracle VM VirtualBox in the Core component, affecting versions prior to 7.0.24 and prior to 7.1.6. This vulnerability allows a high-privileged attacker with access to the environment where Oracle VM VirtualBox runs to compromise the application. Exploitation could lead to unauthorized creation, deletion, or modification of critical data, access to a subset of Oracle VM VirtualBox data, and a partial denial-of-service.
Oracle Life Sciences Argus Safety Login Component Login Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability has been identified in the Oracle Life Sciences Argus Safety product, specifically in version 8.2.3, within the Login component. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the application. Exploitation of this vulnerability requires human interaction from a third party. While the issue resides in Oracle Life Sciences Argus Safety, it may also significantly affect other products, indicating a scope change. Successful exploitation could lead to unauthorized read access to certain data, as well as unauthorized updates, inserts, or deletions of accessible data within Oracle Life Sciences Argus Safety.
Oracle Hyperion Data Relationship Management Web Services Vulnerability Allowing Takeover
A vulnerability has been identified in the Oracle Hyperion Data Relationship Management product, specifically in the Web Services component, version 11.2.19.0.000. This vulnerability is difficult to exploit but allows a high-privileged attacker with network access via HTTP to compromise the application. Successful exploitation can lead to a complete takeover of Oracle Hyperion Data Relationship Management.
Oracle Hyperion Data Relationship Management Access and Security Vulnerability Allowing Unauthorized Data Access
A vulnerability has been identified in Oracle Hyperion Data Relationship Management, specifically in the Access and Security component, version 11.2.19.0.000. This easily exploitable vulnerability allows a high-privileged attacker with network access via HTTP to compromise the application. Successful exploitation, which requires human interaction from a third party, can lead to unauthorized access to critical data or complete access to all data within Oracle Hyperion Data Relationship Management. The vulnerability has a CVSS 3.1 Base Score of 4.5, indicating a confidentiality impact.
Oracle MySQL Server Privilege Vulnerability Allowing Unauthorized Data Access
A vulnerability exists in Oracle MySQL Server in versions through 9.1.0, specifically within the Server: Security: Privileges component. This easily exploitable issue allows a low-privileged attacker with network access via multiple protocols to compromise the MySQL Server. Successful exploitation can lead to unauthorized read access to certain data within the MySQL Server.
Oracle MySQL Server Denial-of-Service Vulnerability in the Optimizer Component
A denial-of-service vulnerability has been identified in Oracle MySQL Server versions through 9.1.0, specifically within the Optimizer component. This vulnerability allows a low-privileged attacker with network access to MySQL Server, via multiple protocols, to cause a hang or a frequently repeatable crash, leading to a complete denial-of-service condition on the server.
Oracle Agile PLM Framework Unauthenticated Data Access Vulnerability
An easily exploitable vulnerability has been identified in the Oracle Agile PLM Framework component of Oracle Supply Chain, specifically in version 9.3.6. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the Agile PLM Framework. Successful exploitation can lead to unauthorized access to critical data or complete access to all data accessible within Oracle Agile PLM Framework.
Oracle Agile PLM Framework Vulnerability in Integration Services Component Allowing Data Access and Denial-of-Service
A vulnerability exists in Oracle Agile PLM Framework, specifically within the Agile Integration Services component, version 9.3.6. This easily exploitable issue allows a low-privileged attacker with network access via HTTP to compromise the Agile PLM Framework. Successful exploitation can lead to unauthorized access to critical data or complete access to all data within the Agile PLM Framework, as well as the ability to cause a complete denial-of-service by hanging the application or causing it to crash frequently and repeatably.
Oracle PeopleSoft CC Common Application Objects Run Control Management Vulnerability Allows Unauthorized Data Modification
A vulnerability exists in the PeopleSoft Enterprise CC Common Application Objects product, specifically within the Run Control Management component, version 9.2. This vulnerability allows a low-privileged attacker with network access via HTTP to perform unauthorized updates, inserts, or deletions of accessible data within the application. The issue arises from insufficient validation of user input, which could be exploited to manipulate data improperly.
Oracle PeopleSoft Enterprise CC Common Application Objects Run Control Management Unauthorized Data Access Vulnerability
A vulnerability exists in the PeopleSoft Enterprise CC Common Application Objects product, specifically within the Run Control Management component, version 9.2. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation can lead to unauthorized read access to certain data within PeopleSoft Enterprise CC Common Application Objects.
Oracle PeopleSoft Enterprise SCM Purchasing Component Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability exists in Oracle PeopleSoft Enterprise SCM Purchasing version 9.2, specifically within the Purchasing component. This easily exploitable issue allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation could lead to unauthorized read, update, insert, or delete access to certain accessible data within PeopleSoft Enterprise SCM Purchasing.
Oracle Agile PLM Framework SDK Unauthorized Data Access Vulnerability
A vulnerability exists in the Oracle Agile PLM Framework component of Oracle Supply Chain, specifically in version 9.3.6. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise the Oracle Agile PLM Framework. Successful exploitation can lead to unauthorized access to critical data or complete access to all data accessible within Oracle Agile PLM Framework.
Oracle MySQL InnoDB Component Denial-of-Service and Data Manipulation Vulnerability
A vulnerability exists in the MySQL Server product of Oracle MySQL, specifically in the InnoDB component. Affected versions include 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. This vulnerability is easily exploitable and allows a high-privileged attacker with network access via multiple protocols to compromise the MySQL Server. Successful exploitation can lead to an unauthorized ability to cause a hang or a frequently repeatable crash, resulting in a complete denial-of-service for the MySQL Server. Additionally, it allows unauthorized update, insert, or delete access to some data accessible by the MySQL Server.
Oracle Primavera P6 EPPM Web Access Vulnerability Allowing Unauthorized Data Access and Modification
A vulnerability has been identified in the Web Access component of Oracle Primavera P6 Enterprise Project Portfolio Management, affecting versions 20.12.1.0 through 20.12.21.5, 21.12.1.0 through 21.12.20.0, and 22.12.1.0. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Primavera P6 EPPM. Exploitation requires human interaction from a third party. While the vulnerability is specific to Primavera P6 EPPM, successful attacks could significantly impact other products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized read access to certain Primavera P6 EPPM data, as well as unauthorized update, insert, or delete access to some accessible data.
Oracle Application Express General Vulnerability Allowing Data Manipulation and Unauthorized Access
A vulnerability has been identified in Oracle Application Express, specifically in versions 23.2 and 24.1. This easily exploitable issue allows a low-privileged attacker with network access via HTTP to compromise Oracle Application Express. Successful exploitation requires human interaction from someone other than the attacker. While the vulnerability resides within Oracle Application Express, its effects may extend to other products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized updates, inserts, or deletions of data accessible through Oracle Application Express, as well as unauthorized read access to certain subsets of that data.
Oracle Agile PLM Framework Integration Services Takeover Vulnerability
A vulnerability allowing takeover of the Oracle Agile PLM Framework has been identified in version 9.3.6 of the product. This easily exploitable issue affects the Agile Integration Services component and allows low privileged attackers with network access via HTTP to compromise the framework. While the vulnerability resides within Oracle Agile PLM Framework, successful exploitation could significantly impact additional products.
