The GarminOS TVM component in CIQ API version 1.0.0...
Critical severity
Unreviewed
Published
May 23, 2023
to the GitHub Advisory Database
•
Updated Jan 31, 2025
Description
Published by the National Vulnerability Database
May 23, 2023
Published to the GitHub Advisory Database
May 23, 2023
Last updated
Jan 31, 2025
The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding specially crafted resources could hijack the execution of the device's firmware.
References