ZeroHour

Vulnerabilities

16 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-7545
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability.

oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of STK command PDUs. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-23458.

NVD description · AI analysis pending
7.8
group max
<1%
  • ofono project ofono
CVE-2023-4234
+3 in the same advisory: …4233 …4232 …4235
A flaw was found in ofono, an Open Source Telephony on Linux.

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_submit_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_submit_report().

NVD description · AI analysis pending
8.11% PoC
  • ofono project ofono
  • ofono project fedora
CVE-2023-2794
A flaw was found in ofono, an Open Source Telephony on Linux.

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_deliver().

NVD description · AI analysis pending
8.11% PoC
  • ofono project ofono
  • ofono project fedora