Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.25% | — | Ofono Project Ofono | 6/8/2024 | 17/6/2026 | oFono SMS Decoder Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific… | |
| Analizada | Alta (7.8) | 0.29% | — | Ofono Project Ofono | 6/8/2024 | 17/6/2026 | oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (7.8) | 0.29% | — | Ofono Project Ofono | 6/8/2024 | 17/6/2026 | oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (7.8) | 0.29% | — | Ofono Project Ofono | 6/8/2024 | 17/6/2026 | oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (7.8) | 0.29% | — | Ofono Project Ofono | 6/8/2024 | 17/6/2026 | oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw… | |
| Analizada | Baja (3.3) | 0.30% | — | Ofono Project Ofono | 6/8/2024 | 17/6/2026 | oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The… | |
| Analizada | Baja (3.3) | 0.30% | — | Ofono Project Ofono | 6/8/2024 | 17/6/2026 | oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The… | |
| Analizada | Baja (3.3) | 0.30% | — | Ofono Project Ofono | 6/8/2024 | 17/6/2026 | oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The… | |
| Analizada | Alta (7.8) | 0.29% | — | Ofono Project Ofono | 6/8/2024 | 17/6/2026 | oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists… | |
| Analizada | Alta (7.8) | 0.29% | — | Ofono Project Ofono | 6/8/2024 | 17/6/2026 | oFono CUSD AT Command Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw… | |
| Analizada | Media (5.5) | 0.30% | — | Ofono Project Ofono | 6/8/2024 | 17/6/2026 | oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SMS message… | |
| Analizada | Media (5.4) | 0.29% | — | Ofofonobsdev Hubbank | 29/4/2024 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to send a specially crafted JavaScript payload to registration and profile forms and trigger the payload when any authenticated user loads the page, resulting in a session takeover. | |
| Analizada | Alta (8.1) | 0.45% | — | Ofofonobsdev Hubbank | 29/4/2024 | 17/6/2026 | SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/user/transaction.php?id=1, /user/credit-debit_transaction.php?id=1,/user/view_transaction. php?id=1 and… | |
| Analizada | Alta (8.1) | 0.45% | — | Ofofonobsdev Hubbank | 29/4/2024 | 17/6/2026 | SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/admin/view_users.php?id=1,/admin/viewloan-trans.php?id=1,/admin/view-deposit.php?id=1,/admin/view-domtrans.php?id=1,… | |
| Analizada | Alta (8.1) | 0.45% | — | Ofofonobsdev Hubbank | 29/4/2024 | 17/6/2026 | SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/accounts/activities.php?id=1, /accounts/view-deposit.php?id=1, /accounts/view_cards. php?id=1, /accounts/wire-transfer.php?id=1… | |
| Analizada | Alta (8.8) | 0.69% | — | Ofofonobsdev Hubbank | 29/4/2024 | 17/6/2026 | Critical unrestricted file upload vulnerability in HubBank affecting version 1.0.2. This vulnerability allows a registered user to upload malicious PHP files via upload document fields, resulting in webshell execution. | |
| Modificada | Alta (8.1) | 0.94% | — | Ofono Project OfonoFedoraproject Fedora | 17/4/2024 | 17/6/2026 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this… | |
| Modificada | Alta (8.1) | 1.1% | — | Ofono Project OfonoFedoraproject Fedora | 17/4/2024 | 17/6/2026 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_submit_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this… | |
| Modificada | Alta (8.1) | 1.0% | — | Ofono Project OfonoFedoraproject Fedora | 17/4/2024 | 17/6/2026 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the sms_decode_address_field() function during the SMS PDU decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. | |
| Modificada | Alta (8.1) | 0.95% | — | Ofono Project OfonoFedoraproject Fedora | 17/4/2024 | 17/6/2026 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this… | |
| Modificada | Alta (8.1) | 1.3% | — | Ofono Project OfonoFedoraproject Fedora | 10/4/2024 | 17/6/2026 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy… |