Vulnerabilities > Linuxfoundation > High

DATE CVE VULNERABILITY TITLE RISK
2025-01-21 CVE-2023-37029 Reachable Assertion vulnerability in Linuxfoundation Magma
Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received.
network
low complexity
linuxfoundation CWE-617
7.5
2025-01-21 CVE-2023-37032 Out-of-bounds Write vulnerability in Linuxfoundation Magma
A Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a NAS packet containing an oversized `Emergency Number List` Information Element.
network
low complexity
linuxfoundation CWE-787
7.5
2025-01-21 CVE-2024-24416 Classic Buffer Overflow vulnerability in Linuxfoundation Magma
The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_access_point_name_ie function at /3gpp/3gpp_24.008_sm_ies.c.
network
low complexity
linuxfoundation CWE-120
7.5
2025-01-21 CVE-2024-24417 Out-of-bounds Read vulnerability in Linuxfoundation Magma
The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c.
network
low complexity
linuxfoundation CWE-125
7.5
2025-01-21 CVE-2024-24418 Classic Buffer Overflow vulnerability in Linuxfoundation Magma
The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_pdn_address function at /nas/ies/PdnAddress.cpp.
network
low complexity
linuxfoundation CWE-120
7.5
2025-01-21 CVE-2024-24419 Classic Buffer Overflow vulnerability in Linuxfoundation Magma
The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_traffic_flow_template_packet_filter function at /3gpp/3gpp_24.008_sm_ies.c.
network
low complexity
linuxfoundation CWE-120
7.5
2025-01-21 CVE-2024-24422 Out-of-bounds Write vulnerability in Linuxfoundation Magma
The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a stack overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c.
network
low complexity
linuxfoundation CWE-787
7.5
2025-01-21 CVE-2024-24423 Out-of-bounds Write vulnerability in Linuxfoundation Magma
The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_esm_message_container function at /nas/ies/EsmMessageContainer.cpp.
network
low complexity
linuxfoundation CWE-787
7.5
2024-11-14 CVE-2022-31668 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other projects.
network
low complexity
linuxfoundation CWE-863
7.7
2024-11-14 CVE-2022-31669 Incorrect Authorization vulnerability in Linuxfoundation Harbor
Harbor fails to validate the user permissions when updating tag immutability policies.  By sending a request to update a tag immutability policy with an id that belongs to a project that the currently authenticated user doesn’t have access to, the attacker could modify tag immutability policies configured in other projects.
network
low complexity
linuxfoundation CWE-863
7.7