GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
21
Go
2,094
Maven
5,000+
npm
3,759
NuGet
678
pip
3,445
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
194 advisories
Filter by severity
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a...
High
Unreviewed
CVE-2023-37013
was published
Jan 22, 2025
A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to...
High
Unreviewed
CVE-2024-24428
was published
Jan 22, 2025
A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in...
High
Unreviewed
CVE-2023-37024
was published
Jan 22, 2025
Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are...
High
Unreviewed
CVE-2023-37029
was published
Jan 22, 2025
A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to...
High
Unreviewed
CVE-2024-24427
was published
Jan 22, 2025
A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1...
High
Unreviewed
CVE-2024-24424
was published
Jan 22, 2025
A reachable assertion in the decode_linked_ti_ie function of Magma <= 1.8.0 (fixed in v1.9 commit...
High
Unreviewed
CVE-2024-24420
was published
Jan 22, 2025
A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to...
High
Unreviewed
CVE-2024-24430
was published
Jan 22, 2025
Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.
High
Unreviewed
CVE-2024-53429
was published
Dec 3, 2024
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen...
High
Unreviewed
CVE-2024-23385
was published
Nov 4, 2024
Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via...
High
Unreviewed
CVE-2024-10455
was published
Oct 28, 2024
In Modem, there is a possible system crash due to a missing bounds check. This could lead to...
High
Unreviewed
CVE-2024-20094
was published
Oct 7, 2024
In wlan firmware, there is a possible firmware assertion due to improper input handling. This...
High
Unreviewed
CVE-2023-32820
was published
Oct 2, 2023
A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure...
High
Unreviewed
CVE-2023-5517
was published
Feb 13, 2024
Client queries that trigger serving stale data and that also require lookups in local...
High
Unreviewed
CVE-2024-4076
was published
Jul 23, 2024
nscd: netgroup cache may terminate daemon on memory allocation failure
The Name Service Cache...
High
Unreviewed
CVE-2024-33601
was published
May 6, 2024
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS...
High
Unreviewed
CVE-2024-34475
was published
May 5, 2024
In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an...
High
Unreviewed
CVE-2024-31744
was published
Apr 19, 2024
Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment...
High
Unreviewed
CVE-2023-43529
was published
May 6, 2024
Transient DOS while processing multiple payload container type with incorrect container length...
High
Unreviewed
CVE-2023-33095
was published
Mar 4, 2024
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
High
Unreviewed
CVE-2023-33096
was published
Mar 4, 2024
Transient DOS in Modem while processing invalid System Information Block 1.
High
Unreviewed
CVE-2023-21646
was published
Sep 5, 2023
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication...
High
Unreviewed
CVE-2022-40504
was published
May 2, 2023
A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks...
High
Unreviewed
CVE-2023-44175
was published
Oct 13, 2023
Transient DOS in Modem while triggering a camping on an 5G cell.
High
Unreviewed
CVE-2023-24843
was published
Oct 3, 2023
ProTip!
Advisories are also available from the
GraphQL API