📦 Ofono

by Ofono Project

🔍 What is Ofono?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-7545

HIGH CVSS 7.8 Aug 6, 2024

This vulnerability allows local attackers to execute arbitrary code with elevated privileges on oFono installations by exploiting a heap-based buffer overflow in the SimToolKit command parser. Attacke...

CVE-2024-7547

HIGH CVSS 7.8 Aug 6, 2024

This is a stack-based buffer overflow vulnerability in oFono's SMS PDU decoder that allows local attackers to execute arbitrary code with service account privileges. Attackers need initial code execut...

CVE-2024-7543

HIGH CVSS 7.8 Aug 6, 2024

This heap-based buffer overflow vulnerability in oFono's SimToolKit (STK) command parser allows local attackers with initial code execution on the target modem to escalate privileges and execute arbit...

CVE-2024-7538

HIGH CVSS 7.8 Aug 6, 2024

This vulnerability in oFono allows local attackers to execute arbitrary code with root privileges by exploiting a stack-based buffer overflow in AT command response parsing. It affects systems running...

CVE-2023-4234

HIGH CVSS 8.1 Apr 17, 2024

CVE-2023-4234 is a stack overflow vulnerability in ofono's SMS decoding function that allows remote code execution. Attackers can exploit this via SMS messages, compromised modems, or malicious base s...

CVE-2023-4232

HIGH CVSS 8.1 Apr 17, 2024

CVE-2023-4232 is a stack overflow vulnerability in ofono's SMS decoding function that allows remote code execution. Attackers can exploit this via SMS messages, compromised modems, or malicious base s...

CVE-2023-2794

HIGH CVSS 8.1 Apr 10, 2024

CVE-2023-2794 is a stack overflow vulnerability in ofono's SMS decoding function that allows remote code execution. It affects Linux systems using ofono for telephony services. Attackers could exploit...

CVE-2024-7537

MEDIUM CVSS 5.5 Aug 6, 2024

This vulnerability in oFono's QMI SMS handling allows local attackers to read beyond allocated buffer boundaries, potentially disclosing sensitive information. Attackers could combine this with other ...