Skip to main content

Vendor/product archive

garmin / connect-iq CVEs

Beta · best-effort

9 CVEs tagged to garmin / connect-iq8 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2023-23306

Published May 23, 2023

The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operati…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23305

Published May 23, 2023

The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding specia…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23304

Published May 23, 2023

The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permis…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23303

Published May 23, 2023

The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copyi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23302

Published May 23, 2023

The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying va…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23301

Published May 23, 2023

The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23300

Published May 23, 2023

The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying d…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23299

Published May 23, 2023

The permission system implemented and enforced by the GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 can be bypassed entirely. A malicious application with speciall…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23298

Published May 23, 2023

The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1