{"id":"CVE-2022-40363","details":"A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a Denial of Service (DoS) via a crafted NFC file.","modified":"2026-08-12T03:51:18.965426797Z","published":"2022-09-29T12:16:40Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/40xxx/CVE-2022-40363.json"},"references":[{"type":"WEB","url":"https://vvx7.io/posts/2022/09/your-amiibos-haunted/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/40xxx/CVE-2022-40363.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-40363"},{"type":"FIX","url":"https://github.com/flipperdevices/flipperzero-firmware/pull/1697"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/flipperdevices/flipperzero-firmware","events":[{"introduced":"0"},{"fixed":"ae9038da3683b6e2819f4f23a7ff0edef54858d9"}],"database_specific":{"source":"DESCRIPTION","extracted_events":[{"introduced":"0"},{"fixed":"v0.65.2"}]}}],"versions":["0.64.3","0.64.2","0.63.3","0.62.1","0.60.2","0.61.1","0.59.1","0.58.1","0.57.0","0.56.1","0.55.1","0.54.0","0.53.0","0.52.3","0.52.2","0.51.0","0.50.0","0.49.0","0.48.1","0.47.0","0.46.1","0.45.2","0.44.1","0.43.1","0.42.1","0.40.1","0.39.0","0.38.1","0.35.0","0.34.0","0.32.0","0.31.2","0.30.1","0.29.0","0.28.2","0.27.1","0.26.1","0.25.0","0.23.1-rc","0.23.1","0.23.0-rc","0.22.0","0.21.0","0.20.0","0.19.0","0.18.0","0.17.0","0.16.0","0.15.0","0.14.0","0.13.0","0.12.0","0.11.0","0.10.0","0.9.0","0.8.0","0.7.0","0.6.1","0.6.0","0.5.2","0.5.1","0.5.0","0.4.1","0.4.0","0.3.0","0.2.0","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-40363.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}