Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-23301

Опубликовано: 23 мая 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

The news MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends past its end. Upon loading the string, the GarminOS TVM component may read out-of-bounds memory.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:garmin:connect-iq:*:*:*:*:*:*:*:*
Версия от 1.0.0 (включая) до 4.1.7 (включая)

EPSS

Процентиль: 52%
0.00289
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 9.8
github
больше 2 лет назад

The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends past its end. Upon loading the string, the GarminOS TVM component may read out-of-bounds memory.

EPSS

Процентиль: 52%
0.00289
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-125