Ofono is a modestly represented telephony and modem management stack used in embedded Linux systems, particularly in mobile devices and IoT applications where cellular connectivity must be controlled at the system level. Its vulnerability profile centers on memory-safety issues—out-of-bounds writes, buffer overflows (both heap and stack based), and improper memory-buffer restrictions—that are characteristic of low-level telecommunications protocol handling. Defenders integrating this software should apply patches in sequence and review modem-facing attack surface exposure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ofono Project over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4235HIGH A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver_report() function during the SMS decoding. It is assumed t | Apr 17, 2024 | 8.1 | 26 | NO | NO |
CVE-2023-4232HIGH A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed th | Apr 17, 2024 | 8.1 | 26 | NO | NO |
CVE-2023-2794HIGH A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS decoding. It is assumed that the | Apr 10, 2024 | 8.1 | 25 | NO | NO |
CVE-2023-4234HIGH A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_submit_report() function during the SMS decoding. It is assumed th | Apr 17, 2024 | 8.1 | 24 | NO | NO |
CVE-2024-7547HIGH oFono SMS Decoder Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of o | Aug 6, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-7546HIGH oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFo | Aug 6, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-7545HIGH oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFo | Aug 6, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-7544HIGH oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFo | Aug 6, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-7543HIGH oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFo | Aug 6, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-7539HIGH oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An atta | Aug 6, 2024 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ofono Project.
Media articles that mention a CVE ID that affects a product developed by Ofono Project — matched by CVE ID, not by vendor name.