garmin kayıtları
garmin üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-129 Improper Validation of Array Index2
- CWE-190 Integer Overflow or Wraparound2
- CWE-863 Incorrect Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-27483İstismar yok | Garmin Forerunner 235 before 8.20 is affected by: Array index error.garmin · forerunner 235 firmware · CWE-129 | Kritik9,9 | — | %2,1 | 16 Kas 2020 |
40Planlayın | CVE-2020-27486İstismar yok | Garmin Forerunner 235 before 8.20 is affected by: Buffer Overflow.garmin · forerunner 235 firmware · CWE-120 | Kritik9,9 | — | %1,9 | 16 Kas 2020 |
40Planlayın | CVE-2020-27484İstismar yok | Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow.garmin · forerunner 235 firmware · CWE-190 | Kritik9,9 | — | %1,8 | 16 Kas 2020 |
40Planlayın | CVE-2020-27485İstismar yok | Garmin Forerunner 235 before 8.20 is affected by: Array index error.garmin · forerunner 235 firmware · CWE-129 | Kritik9,9 | — | %1,7 | 16 Kas 2020 |
39İzleyin | CVE-2023-23298İstismar yok | The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which cagarmin · connect-iq · CWE-190 | Kritik9,8 | — | %1,5 | 23 May 2023 |
39İzleyin | CVE-2023-23305İstismar yok | The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources.garmin · connect-iq · CWE-120 | Kritik9,8 | — | %1,3 | 23 May 2023 |
39İzleyin | CVE-2023-23300İstismar yok | The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can regarmin · connect-iq · CWE-120 | Kritik9,8 | — | %1,3 | 23 May 2023 |
39İzleyin | CVE-2023-23302İstismar yok | The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can resgarmin · connect-iq · CWE-120 | Kritik9,8 | — | %1,3 | 23 May 2023 |
39İzleyin | CVE-2023-23306İstismar yok | The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can rgarmin · connect-iq · CWE-787 | Kritik9,8 | — | %1,2 | 23 May 2023 |
39İzleyin | CVE-2023-23301İstismar yok | The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the endgarmin · connect-iq · CWE-125 | Kritik9,8 | — | %1,1 | 23 May 2023 |
39İzleyin | CVE-2023-23303İstismar yok | The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which cagarmin · connect-iq · CWE-120 | Kritik9,8 | — | %0,8 | 23 May 2023 |
38İzleyin | CVE-2009-0194İstismar yok | The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garmin Communicator Pluggarmin · garmin communicator plugin · CWE-264 | Kritik9,3 | — | %2,3 | 11 May 2009 |
37İzleyin | CVE-2025-27851İstismar yok | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack.garmin · empirbus wireless display unit firmware · CWE-352 | Kritik9,3 | — | %0,1 | 13 May 2026 |
36İzleyin | CVE-2023-23304İstismar yok | The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybgarmin · connect-iq · CWE-863 | Kritik9,1 | — | %0,6 | 23 May 2023 |
30İzleyin | CVE-2023-23299İstismar yok | The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirelygarmin · connect-iq · CWE-863 | Yüksek7,5 | — | %0,8 | 23 May 2023 |
30İzleyin | CVE-2022-46081İstismar yok | In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from continued exposure of private personal inforgarmin · connect · CWE-200 | Yüksek7,5 | — | %0,7 | 4 Oca 2023 |
30İzleyin | CVE-2025-27850İstismar yok | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack.garmin · empirbus wireless display unit firmware · CWE-59 | Yüksek7,5 | — | %0,4 | 13 May 2026 |
29İzleyin | CVE-2025-27853İstismar yok | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed.garmin · empirbus wireless display unit firmware · CWE-306 | Yüksek7,3 | — | %0,3 | 13 May 2026 |
20İzleyin | CVE-2025-27852İstismar yok | The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack.garmin · empirbus wireless display unit firmware · CWE-79 | Orta5,0 | — | %0,1 | 13 May 2026 |
- CVE-2020-2748340Planlayın
Garmin Forerunner 235 before 8.20 is affected by: Array index error.
KritikCVSS 9,9İstismar yokEPSS %2garmin · forerunner 235 firmware16 Kas 2020
- CVE-2020-2748640Planlayın
Garmin Forerunner 235 before 8.20 is affected by: Buffer Overflow.
KritikCVSS 9,9İstismar yokEPSS %2garmin · forerunner 235 firmware16 Kas 2020
- CVE-2020-2748440Planlayın
Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow.
KritikCVSS 9,9İstismar yokEPSS %2garmin · forerunner 235 firmware16 Kas 2020
- CVE-2020-2748540Planlayın
Garmin Forerunner 235 before 8.20 is affected by: Array index error.
KritikCVSS 9,9İstismar yokEPSS %2garmin · forerunner 235 firmware16 Kas 2020
- CVE-2023-2329839İzleyin
The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which ca
KritikCVSS 9,8İstismar yokEPSS %1garmin · connect-iq23 May 2023
- CVE-2023-2330539İzleyin
The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources.
KritikCVSS 9,8İstismar yokEPSS %1garmin · connect-iq23 May 2023
- CVE-2023-2330039İzleyin
The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can re
KritikCVSS 9,8İstismar yokEPSS %1garmin · connect-iq23 May 2023
- CVE-2023-2330239İzleyin
The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can res
KritikCVSS 9,8İstismar yokEPSS %1garmin · connect-iq23 May 2023
- CVE-2023-2330639İzleyin
The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can r
KritikCVSS 9,8İstismar yokEPSS %1garmin · connect-iq23 May 2023
- CVE-2023-2330139İzleyin
The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end
KritikCVSS 9,8İstismar yokEPSS %1garmin · connect-iq23 May 2023
- CVE-2023-2330339İzleyin
The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which ca
KritikCVSS 9,8İstismar yokEPSS %1garmin · connect-iq23 May 2023
- CVE-2009-019438İzleyin
The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garmin Communicator Plug
KritikCVSS 9,3İstismar yokEPSS %2garmin · garmin communicator plugin11 May 2009
- CVE-2025-2785137İzleyin
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack.
KritikCVSS 9,3İstismar yokEPSS %0garmin · empirbus wireless display unit firmware13 May 2026
- CVE-2023-2330436İzleyin
The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toyb
KritikCVSS 9,1İstismar yokEPSS %1garmin · connect-iq23 May 2023
- CVE-2023-2329930İzleyin
The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely
YüksekCVSS 7,5İstismar yokEPSS %1garmin · connect-iq23 May 2023
- CVE-2022-4608130İzleyin
In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from continued exposure of private personal infor
YüksekCVSS 7,5İstismar yokEPSS %1garmin · connect4 Oca 2023
- CVE-2025-2785030İzleyin
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack.
YüksekCVSS 7,5İstismar yokEPSS %0garmin · empirbus wireless display unit firmware13 May 2026
- CVE-2025-2785329İzleyin
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed.
YüksekCVSS 7,3İstismar yokEPSS %0garmin · empirbus wireless display unit firmware13 May 2026
- CVE-2025-2785220İzleyin
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack.
OrtaCVSS 5,0İstismar yokEPSS %0garmin · empirbus wireless display unit firmware13 May 2026