Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-27401 | The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends past its end. Upon loading the string, the GarminOS TVM component may read out-of-bounds memory. |
Tue, 21 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-21T14:50:39.670Z
Reserved: 2023-01-11T00:00:00.000Z
Link: CVE-2023-23301
Updated: 2024-08-02T10:28:40.605Z
Status : Modified
Published: 2023-05-23T20:15:09.427
Modified: 2024-11-21T07:45:58.113
Link: CVE-2023-23301
No data.
OpenCVE Enrichment
No data.
EUVD