Vendor CVEs
Motorola
All CVEs
145 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-3407 | Med | 0.32 | 4.9 | 0.00 | Sep 1, 2023 | I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user… | ||
| CVE-2023-41822 | Med | 0.31 | 4.8 | 0.00 | May 3, 2024 | An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands. | ||
| CVE-2021-38701 | Med | 0.31 | 4.8 | 0.00 | Dec 15, 2021 | Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180. | ||
| CVE-2024-38280 | Med | 0.30 | 4.6 | 0.00 | Jun 13, 2024 | An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text. | ||
| CVE-2024-38279 | Med | 0.30 | 4.6 | 0.00 | Jun 13, 2024 | The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes. | ||
| CVE-2022-3917 | Med | 0.30 | 4.6 | 0.00 | Dec 14, 2022 | Improper access control of bootloader function was discovered in Motorola Mobility Motorola e20 prior to version RONS31.267-38-8 allows attacker with local access to read partition or RAM data. | ||
| CVE-2017-9495 | Med | 0.30 | 4.6 | 0.00 | Jul 31, 2017 | The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to read arbitrary files by pressing "EXIT, Down, Down, 2" on an RF4CE remote to reach the diagnostic display, and then launching a Remote Web… | ||
| CVE-2023-41828 | Med | 0.29 | 4.4 | 0.00 | May 3, 2024 | An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider. | ||
| CVE-2023-41823 | Med | 0.29 | 4.4 | 0.00 | May 3, 2024 | An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities. | ||
| CVE-2021-3789 | Med | 0.27 | 4.2 | 0.00 | Nov 12, 2021 | An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages. | ||
| CVE-2025-2818 | Low | 0.23 | 3.5 | 0.00 | Jul 17, 2025 | A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby attacker within the Bluetooth interaction range to intercept files when transferred to a device not paired… | ||
| CVE-2023-38301 | Low | 0.22 | 3.4 | 0.00 | Apr 22, 2024 | An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers. Various software builds for the BLU View 2, Boost Mobile Celero 5G, Sharp Rouvo V, Motorola Moto G Pure, Motorola Moto G Power, T-Mobile Revvl… | ||
| CVE-2025-1699 | Low | 0.18 | 2.8 | 0.00 | Jun 11, 2025 | An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access. | ||
| CVE-2025-1698 | Low | 0.18 | 2.8 | 0.00 | Jun 11, 2025 | Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial of service. | ||
| CVE-2022-4003 | Low | 0.18 | 2.7 | 0.00 | Jul 31, 2024 | A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request. | ||
| CVE-2024-3480 | Low | 0.18 | 2.8 | 0.00 | May 3, 2024 | An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data. | ||
| CVE-2024-3479 | Low | 0.18 | 2.8 | 0.00 | May 3, 2024 | An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data. | ||
| CVE-2023-41825 | Low | 0.18 | 2.8 | 0.00 | May 3, 2024 | A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files. | ||
| CVE-2023-41824 | Low | 0.18 | 2.8 | 0.00 | May 3, 2024 | An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data. | ||
| CVE-2023-41817 | Low | 0.18 | 2.8 | 0.00 | May 3, 2024 | An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information. | ||
| CVE-2009-1394 | 0.06 | — | 0.33 | Jun 26, 2009 | Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand named pipe. | |||
| CVE-2010-2307 | 0.04 | — | 0.09 | Jun 16, 2010 | Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded… | |||
| CVE-2006-5196 | 0.04 | — | 0.07 | Oct 10, 2006 | The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter. | |||
| CVE-2004-1550 | 0.04 | — | 0.19 | Dec 31, 2004 | Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP request for ver.asp until an administrator logs on. | |||
| CVE-2009-0393 | 0.03 | — | 0.01 | Feb 3, 2009 | Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter. | |||
| CVE-2009-0392 | 0.03 | — | 0.02 | Feb 3, 2009 | Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter. | |||
| CVE-2007-4220 | 0.03 | — | 0.04 | Aug 29, 2007 | Directory traversal vulnerability in Motorola Timbuktu Pro before 8.6.5 for Windows allows remote attackers to create or delete arbitrary files via a .. (dot dot) in a Send request, probably related to the (1) Send and (2) Exchange services. | |||
| CVE-2006-1367 | 0.03 | — | 0.03 | Mar 23, 2006 | The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a connection related to the Headset Audio Gateway service, which allows user-assisted remote attackers to obtain AT level access and… | |||
| CVE-2007-4221 | 0.01 | — | 0.06 | Aug 29, 2007 | Multiple buffer overflows in Motorola Timbuktu Pro before 8.6.5 for Windows allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via (1) a long user name and (2) certain malformed requests; and (3) allow remote Timbuktu servers to… | |||
| CVE-2015-1496 | 0.00 | — | 0.00 | Feb 16, 2015 | Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerService.exe, which allows local users to gain privileges via unspecified vectors. | |||
| CVE-2015-1495 | 0.00 | — | 0.03 | Feb 16, 2015 | Multiple stack-based buffer overflows in Motorola Scanner SDK allow remote attackers to execute arbitrary code via a crafted string to the Open method in (1) IOPOSScanner.ocx or (2) IOPOSScale.ocx. | |||
| CVE-2013-5933 | 0.00 | — | 0.00 | Sep 25, 2013 | Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless allows local users to gain privileges or cause a denial of service (memory corruption) by writing a long string to the… | |||
| CVE-2013-4777 | 0.00 | — | 0.00 | Sep 25, 2013 | A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that listens for shell commands, which allows local users to gain privileges by interacting with a LocalSocket object. | |||
| CVE-2013-3051 | 0.00 | — | 0.00 | Apr 13, 2013 | The TrustZone kernel, when used in conjunction with a certain Motorola build of Android 4.1.2, on Motorola Razr HD, Razr M, and Atrix HD devices with the Qualcomm MSM8960 chipset does not verify the association between a certain physical-address argument and a memory region,… | |||
| CVE-2008-2548 | 0.00 | — | 0.06 | Jun 4, 2008 | Stack-based buffer overflow in the JPEG thumbprint component in the EXIF parser on Motorola cell phones with RAZR firmware allows user-assisted remote attackers to execute arbitrary code via an MMS transmission of a malformed JPEG image, which triggers memory corruption. | |||
| CVE-2008-2002 | 0.00 | — | 0.01 | Apr 28, 2008 | Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (device reboot) via the "Restart Cable Modem" value in the BUTTON_INPUT parameter to configdata.html,… | |||
| CVE-2007-5761 | 0.00 | — | 0.00 | Jan 9, 2008 | The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the… | |||
| CVE-2007-5792 | 0.00 | — | 0.01 | Nov 1, 2007 | The Vonage Motorola Phone Adapter VT 2142-VD does not encrypt RTP packets, which might allow remote attackers to eavesdrop by sniffing the network and reconstructing the RTP session. | |||
| CVE-2007-0522 | 0.00 | — | 0.01 | Jan 26, 2007 | The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push. | |||
| CVE-2006-1366 | 0.00 | — | 0.05 | Mar 23, 2006 | Buffer overflow in the Motorola PEBL U6 08.83.76R, and possibly other Motorola P2K-based phones, allows remote attackers to cause a denial of service (device shutdown), and possibly execute arbitrary code, via a long OBEX setpath to the OBEX File Transfer (aka FTP) service on… | |||
| CVE-2006-1365 | 0.00 | — | 0.01 | Mar 23, 2006 | The Motorola PEBL U6, the Motorola V600, and possibly the Motorola E398 and other Motorola phones allow remote attackers to add an entry for their own Bluetooth device to a target device's list of trusted devices (aka Device History), and possibly obtain AT level access to the… | |||
| CVE-2005-4215 | 0.00 | — | 0.02 | Dec 14, 2005 | Motorola SB5100E Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND). | |||
| CVE-2002-1944 | 0.00 | — | 0.02 | Dec 31, 2002 | Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap. | |||
| CVE-1999-0919 | 0.00 | — | 0.03 | May 10, 1998 | A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections. | |||
| CVE-1999-0816 | 0.00 | — | 0.03 | May 10, 1998 | The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024. |
- risk 0.32cvss 4.9epss 0.00
I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user…
- risk 0.31cvss 4.8epss 0.00
An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.
- risk 0.31cvss 4.8epss 0.00
Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180.
- risk 0.30cvss 4.6epss 0.00
An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.
- risk 0.30cvss 4.6epss 0.00
The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
- risk 0.30cvss 4.6epss 0.00
Improper access control of bootloader function was discovered in Motorola Mobility Motorola e20 prior to version RONS31.267-38-8 allows attacker with local access to read partition or RAM data.
- risk 0.30cvss 4.6epss 0.00
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to read arbitrary files by pressing "EXIT, Down, Down, 2" on an RF4CE remote to reach the diagnostic display, and then launching a Remote Web…
- risk 0.29cvss 4.4epss 0.00
An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.
- risk 0.29cvss 4.4epss 0.00
An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities.
- risk 0.27cvss 4.2epss 0.00
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages.
- risk 0.23cvss 3.5epss 0.00
A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby attacker within the Bluetooth interaction range to intercept files when transferred to a device not paired…
- risk 0.22cvss 3.4epss 0.00
An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers. Various software builds for the BLU View 2, Boost Mobile Celero 5G, Sharp Rouvo V, Motorola Moto G Pure, Motorola Moto G Power, T-Mobile Revvl…
- risk 0.18cvss 2.8epss 0.00
An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access.
- risk 0.18cvss 2.8epss 0.00
Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial of service.
- risk 0.18cvss 2.7epss 0.00
A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.
- risk 0.18cvss 2.8epss 0.00
An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data.
- risk 0.18cvss 2.8epss 0.00
An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data.
- risk 0.18cvss 2.8epss 0.00
A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files.
- risk 0.18cvss 2.8epss 0.00
An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data.
- risk 0.18cvss 2.8epss 0.00
An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information.
- CVE-2009-1394Jun 26, 2009risk 0.06cvss —epss 0.33
Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand named pipe.
- CVE-2010-2307Jun 16, 2010risk 0.04cvss —epss 0.09
Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded…
- CVE-2006-5196Oct 10, 2006risk 0.04cvss —epss 0.07
The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter.
- CVE-2004-1550Dec 31, 2004risk 0.04cvss —epss 0.19
Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP request for ver.asp until an administrator logs on.
- CVE-2009-0393Feb 3, 2009risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.
- CVE-2009-0392Feb 3, 2009risk 0.03cvss —epss 0.02
Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter.
- CVE-2007-4220Aug 29, 2007risk 0.03cvss —epss 0.04
Directory traversal vulnerability in Motorola Timbuktu Pro before 8.6.5 for Windows allows remote attackers to create or delete arbitrary files via a .. (dot dot) in a Send request, probably related to the (1) Send and (2) Exchange services.
- CVE-2006-1367Mar 23, 2006risk 0.03cvss —epss 0.03
The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a connection related to the Headset Audio Gateway service, which allows user-assisted remote attackers to obtain AT level access and…
- CVE-2007-4221Aug 29, 2007risk 0.01cvss —epss 0.06
Multiple buffer overflows in Motorola Timbuktu Pro before 8.6.5 for Windows allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via (1) a long user name and (2) certain malformed requests; and (3) allow remote Timbuktu servers to…
- CVE-2015-1496Feb 16, 2015risk 0.00cvss —epss 0.00
Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerService.exe, which allows local users to gain privileges via unspecified vectors.
- CVE-2015-1495Feb 16, 2015risk 0.00cvss —epss 0.03
Multiple stack-based buffer overflows in Motorola Scanner SDK allow remote attackers to execute arbitrary code via a crafted string to the Open method in (1) IOPOSScanner.ocx or (2) IOPOSScale.ocx.
- CVE-2013-5933Sep 25, 2013risk 0.00cvss —epss 0.00
Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless allows local users to gain privileges or cause a denial of service (memory corruption) by writing a long string to the…
- CVE-2013-4777Sep 25, 2013risk 0.00cvss —epss 0.00
A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that listens for shell commands, which allows local users to gain privileges by interacting with a LocalSocket object.
- CVE-2013-3051Apr 13, 2013risk 0.00cvss —epss 0.00
The TrustZone kernel, when used in conjunction with a certain Motorola build of Android 4.1.2, on Motorola Razr HD, Razr M, and Atrix HD devices with the Qualcomm MSM8960 chipset does not verify the association between a certain physical-address argument and a memory region,…
- CVE-2008-2548Jun 4, 2008risk 0.00cvss —epss 0.06
Stack-based buffer overflow in the JPEG thumbprint component in the EXIF parser on Motorola cell phones with RAZR firmware allows user-assisted remote attackers to execute arbitrary code via an MMS transmission of a malformed JPEG image, which triggers memory corruption.
- CVE-2008-2002Apr 28, 2008risk 0.00cvss —epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (device reboot) via the "Restart Cable Modem" value in the BUTTON_INPUT parameter to configdata.html,…
- CVE-2007-5761Jan 9, 2008risk 0.00cvss —epss 0.00
The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the…
- CVE-2007-5792Nov 1, 2007risk 0.00cvss —epss 0.01
The Vonage Motorola Phone Adapter VT 2142-VD does not encrypt RTP packets, which might allow remote attackers to eavesdrop by sniffing the network and reconstructing the RTP session.
- CVE-2007-0522Jan 26, 2007risk 0.00cvss —epss 0.01
The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.
- CVE-2006-1366Mar 23, 2006risk 0.00cvss —epss 0.05
Buffer overflow in the Motorola PEBL U6 08.83.76R, and possibly other Motorola P2K-based phones, allows remote attackers to cause a denial of service (device shutdown), and possibly execute arbitrary code, via a long OBEX setpath to the OBEX File Transfer (aka FTP) service on…
- CVE-2006-1365Mar 23, 2006risk 0.00cvss —epss 0.01
The Motorola PEBL U6, the Motorola V600, and possibly the Motorola E398 and other Motorola phones allow remote attackers to add an entry for their own Bluetooth device to a target device's list of trusted devices (aka Device History), and possibly obtain AT level access to the…
- CVE-2005-4215Dec 14, 2005risk 0.00cvss —epss 0.02
Motorola SB5100E Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND).
- CVE-2002-1944Dec 31, 2002risk 0.00cvss —epss 0.02
Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap.
- CVE-1999-0919May 10, 1998risk 0.00cvss —epss 0.03
A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.
- CVE-1999-0816May 10, 1998risk 0.00cvss —epss 0.03
The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.
Page 3 of 3