Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Uip HIGH 7.5
CVE-2020-24335

An issue was discovered in uIP through 1.0, as used in Contiki and Contiki-NG. Domain name parsing lacks bounds checks, allowing an attacker to corru…

Fix: after 1.0
Fix from $1,950 2021-02-02
Uip HIGH 8.2
CVE-2020-24334

The code that processes DNS responses in uIP through 1.0, as used in Contiki and Contiki-NG, does not check whether the number of responses specified…

Fix: after 1.0
Fix from $1,950 2020-12-11
Uip HIGH 7.5
CVE-2020-17440

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that domai…

Mitigation only
Fix from $1,950 2020-12-11
Uip CRITICAL 9.8
CVE-2020-17438EPSS 19%

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validat…

Mitigation only
Fix from $2,300 2020-12-11
Uip HIGH 8.3
CVE-2020-17439

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets does not validate that the i…

Mitigation only
Fix from $1,950 2020-12-11
Uip HIGH 8.2
CVE-2020-17437

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configur…

Fix: 2.4.7 / 3.2.2+
Fix from $1,950 2020-12-11
Uip HIGH 7.5
CVE-2020-13987

An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the che…

Fix: 2.3.0 / 2.4.7+
Fix from $1,950 2020-12-11