Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ofono Project

First CVE: Apr 10, 2024Active for: 2 yearsTotal CVEs: 16
36.0
VTI Score
Medium

Ofono is a modestly represented telephony and modem management stack used in embedded Linux systems, particularly in mobile devices and IoT applications where cellular connectivity must be controlled at the system level. Its vulnerability profile centers on memory-safety issues—out-of-bounds writes, buffer overflows (both heap and stack based), and improper memory-buffer restrictions—that are characteristic of low-level telecommunications protocol handling. Defenders integrating this software should apply patches in sequence and review modem-facing attack surface exposure; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
16.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ofono Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2024
2 years ago
Most Recent CVE
Aug 6, 2024
718 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-4235HIGH
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver_report() function during the SMS decoding. It is assumed t
Apr 17, 20248.126NONO
CVE-2023-4232HIGH
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed th
Apr 17, 20248.126NONO
CVE-2023-2794HIGH
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS decoding. It is assumed that the
Apr 10, 20248.125NONO
CVE-2023-4234HIGH
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_submit_report() function during the SMS decoding. It is assumed th
Apr 17, 20248.124NONO
CVE-2024-7547HIGH
oFono SMS Decoder Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of o
Aug 6, 20247.823NONO
CVE-2024-7546HIGH
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFo
Aug 6, 20247.823NONO
CVE-2024-7545HIGH
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFo
Aug 6, 20247.823NONO
CVE-2024-7544HIGH
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFo
Aug 6, 20247.823NONO
CVE-2024-7543HIGH
oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFo
Aug 6, 20247.823NONO
CVE-2024-7539HIGH
oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An atta
Aug 6, 20247.823NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
19%
75%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local11 (68.8%)
Network5 (31.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (68.8%)
High5 (31.3%)
Unknown0 (0.0%)
User Interaction
None16 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low11 (68.8%)
High0 (0.0%)
None5 (31.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ofono Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ofono Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ofono Project's Products

View all 2 CNAs →

Top CWEs