İçeriğe atla
Noroxi

garmin kayıtları

garmin üreticisine ait 19 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

19 kayıt
  • CVE-2020-27483
    40Planlayın

    Garmin Forerunner 235 before 8.20 is affected by: Array index error.

    KritikCVSS 9,9İstismar yokEPSS %2

    garmin · forerunner 235 firmware16 Kas 2020

  • CVE-2020-27486
    40Planlayın

    Garmin Forerunner 235 before 8.20 is affected by: Buffer Overflow.

    KritikCVSS 9,9İstismar yokEPSS %2

    garmin · forerunner 235 firmware16 Kas 2020

  • CVE-2020-27484
    40Planlayın

    Garmin Forerunner 235 before 8.20 is affected by: Integer Overflow.

    KritikCVSS 9,9İstismar yokEPSS %2

    garmin · forerunner 235 firmware16 Kas 2020

  • CVE-2020-27485
    40Planlayın

    Garmin Forerunner 235 before 8.20 is affected by: Array index error.

    KritikCVSS 9,9İstismar yokEPSS %2

    garmin · forerunner 235 firmware16 Kas 2020

  • CVE-2023-23298
    39İzleyin

    The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which ca

    KritikCVSS 9,8İstismar yokEPSS %1

    garmin · connect-iq23 May 2023

  • CVE-2023-23305
    39İzleyin

    The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources.

    KritikCVSS 9,8İstismar yokEPSS %1

    garmin · connect-iq23 May 2023

  • CVE-2023-23300
    39İzleyin

    The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can re

    KritikCVSS 9,8İstismar yokEPSS %1

    garmin · connect-iq23 May 2023

  • CVE-2023-23302
    39İzleyin

    The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can res

    KritikCVSS 9,8İstismar yokEPSS %1

    garmin · connect-iq23 May 2023

  • CVE-2023-23306
    39İzleyin

    The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can r

    KritikCVSS 9,8İstismar yokEPSS %1

    garmin · connect-iq23 May 2023

  • CVE-2023-23301
    39İzleyin

    The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end

    KritikCVSS 9,8İstismar yokEPSS %1

    garmin · connect-iq23 May 2023

  • CVE-2023-23303
    39İzleyin

    The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which ca

    KritikCVSS 9,8İstismar yokEPSS %1

    garmin · connect-iq23 May 2023

  • CVE-2009-0194
    38İzleyin

    The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garmin Communicator Plug

    KritikCVSS 9,3İstismar yokEPSS %2

    garmin · garmin communicator plugin11 May 2009

  • CVE-2025-27851
    37İzleyin

    The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack.

    KritikCVSS 9,3İstismar yokEPSS %0

    garmin · empirbus wireless display unit firmware13 May 2026

  • CVE-2023-23304
    36İzleyin

    The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toyb

    KritikCVSS 9,1İstismar yokEPSS %1

    garmin · connect-iq23 May 2023

  • CVE-2023-23299
    30İzleyin

    The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely

    YüksekCVSS 7,5İstismar yokEPSS %1

    garmin · connect-iq23 May 2023

  • CVE-2022-46081
    30İzleyin

    In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from continued exposure of private personal infor

    YüksekCVSS 7,5İstismar yokEPSS %1

    garmin · connect4 Oca 2023

  • CVE-2025-27850
    30İzleyin

    The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack.

    YüksekCVSS 7,5İstismar yokEPSS %0

    garmin · empirbus wireless display unit firmware13 May 2026

  • CVE-2025-27853
    29İzleyin

    The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed.

    YüksekCVSS 7,3İstismar yokEPSS %0

    garmin · empirbus wireless display unit firmware13 May 2026

  • CVE-2025-27852
    20İzleyin

    The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack.

    OrtaCVSS 5,0İstismar yokEPSS %0

    garmin · empirbus wireless display unit firmware13 May 2026