Linux Vulnerabilities and Affected Products
Vulnerabilities associated with ofono.
Products
Clear product- Linux13,800 vulnerabilities
- linux_kernel169 vulnerabilities
- Kernel144 vulnerabilities
- Linux Kernel42 vulnerabilities
- acrn3 vulnerabilities
- ofono2 vulnerabilities
- buildroot1 vulnerability
- dnf51 vulnerability
- kernel:1 vulnerability
- Linux Kernal1 vulnerability
- util-linux1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-4234HIGH | Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_submit_report() functionA flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_submit_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_submit_report(). | CVSS8.1v3.1 | EPSS1.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2794HIGH | Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_deliver() functionA flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_deliver(). CWE-119Apr 10, 2024 | CVSS8.1v3.1 | EPSS1.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |