CVE-2024-47248
published 2024-11-26CVE-2024-47248: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafted MESH message could result in memory…
PriorityP431medium6.3CVSS 3.1
AVAACLPRNUINSUCLILAL
EPSS
0.69%
48.6th percentile
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
Specially crafted MESH message could result in memory corruption when non-default build configuration is used.
This issue affects Apache NimBLE: through 1.7.0.
Users are recommended to upgrade to version 1.8.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nimble | < 1.8.0 | 1.8.0 |
| apache_software_foundation | apache_nimble | <= 1.7.0 | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f94q-ffqr-x638: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE
ghsa_unreviewed·2024-11-26
CVE-2024-47248 [MEDIUM] CWE-120 GHSA-f94q-ffqr-x638: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE.
Specially crafted MESH message could result in memory corruption when non-default build configuration is used.
This issue affects Apache NimBLE: through 1.7.0.
Users are recommended to upgrade to version 1.8.0, which fixes the issue.
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Installer (PyArrow) — CVE-2023-47248
vendor_oracle·2024-07-15·CVSS 9.8
CVE-2023-47248 [CRITICAL] Oracle Oracle Financial Services Applications Risk Matrix: Installer (PyArrow) — CVE-2023-47248
Oracle Oracle Financial Services Applications Risk Matrix: Installer (PyArrow) vulnerability
CVE: CVE-2023-47248
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-11-26
Published