Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vxworks HIGH 7.5
CVE-2023-51787

An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task memory i…

Mitigation only
Fix from $1,950 2024-02-15
Vxworks HIGH 8.8
CVE-2023-38346

An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files …

Patch available
Fix from $1,950 2023-09-22
Vxworks HIGH 7.5
CVE-2022-38767

An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Servi…

Fix: 6.9.4.12+
Fix from $1,950 2022-11-25
Vxworks HIGH 7.5
CVE-2022-23937

In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario.

Mitigation only
Fix from $1,950 2022-03-29
Vxworks MEDIUM 6.5
CVE-2021-43268

An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer,…

Fix: after 7.0
Fix from $1,600 2021-11-24
Vxworks CRITICAL 9.8
CVE-2020-35198

An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allo…

Fix: 6.9.4.12 / 21.03+
Fix from $2,300 2021-05-12
Vxworks CRITICAL 9.8
CVE-2021-29998

An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.

Fix: 6.5+
Fix from $2,300 2021-04-13
Vxworks CRITICAL 9.8
CVE-2021-29999

An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server.

Fix: after 6.8
Fix from $2,300 2021-04-13
Vxworks MEDIUM 5.3
CVE-2021-29997

An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE.

Fix: 21.03+
Fix from $1,600 2021-04-13
Vxworks CRITICAL 9.8
CVE-2016-20009

A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects prod…

Fix: after 7.0
Fix from $2,300 2021-03-11
Vxworks HIGH 7.3
CVE-2020-28895

In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the …

Fix: 6.9.4.12+
Fix from $1,950 2021-02-03
Vxworks HIGH 7.5
CVE-2020-11440

httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root.

Fix: 7.0+
Fix from $1,950 2020-07-23
Vxworks HIGH 7.5
CVE-2020-10664

The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference.

Mitigation only
Fix from $1,950 2020-04-27
Vxworks CRITICAL 9.8
CVE-2019-12262

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unso…

Fix: after 07.5.01
Fix from $2,300 2019-08-14
Vxworks CRITICAL 9.8
CVE-2019-12260EPSS 23%

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer…

Fix: 2.2.1 / 6.9.4.12+
Fix from $2,300 2019-08-09
Vxworks CRITICAL 9.8
CVE-2019-12261EPSS 9%

Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urg…

Fix: 2.2.1 / 6.9.4.12+
Fix from $2,300 2019-08-09
Vxworks CRITICAL 9.8
CVE-2019-12255EPSS 75%

Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that lea…

Fix: 2.2.1 / 6.9.4+
Fix from $2,300 2019-08-09
Vxworks HIGH 7.5
CVE-2019-12258EPSS 23%

Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malfo…

Fix: 2.2.1 / 6.9.4.12+
Fix from $1,950 2019-08-09
Vxworks HIGH 8.1
CVE-2019-12263

Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Poin…

Fix: 2.2.1 / 6.9.4.12+
Fix from $1,950 2019-08-09
Vxworks HIGH 7.5
CVE-2019-12259EPSS 16%

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS …

Fix: 2.2.1 / 6.9.4.12+
Fix from $1,950 2019-08-09
Vxworks MEDIUM 5.3
CVE-2019-12265EPSS 60%

Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IG…

Fix: 2.2.1 / 6.9.4.12+
Fix from $1,600 2019-08-09
Vxworks CRITICAL 9.8
CVE-2019-12256EPSS 27%

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing o…

Fix: 2.2.1 / 6.9.4.12+
Fix from $2,300 2019-08-09
Vxworks HIGH 8.8
CVE-2019-12257EPSS 84%

Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHC…

Fix: 6.9.4 / 7.59+
Fix from $1,950 2019-08-09
Vxworks HIGH 7.1
CVE-2019-12264EPSS 8%

Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.

Fix: after 07.5.01
Fix from $1,950 2019-08-05
Vxworks HIGH 8.1
CVE-2019-9865

When RPC is enabled in Wind River VxWorks 6.9 prior to 6.9.1, a specially crafted RPC request can trigger an integer overflow leading to an out-of-bo…

Fix: 6.9.1+
Fix from $1,950 2019-05-29
Vxworks HIGH 8.1
CVE-2015-7599EPSS 6%

Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol…

Fix: after 6.9.4.1
Fix from $1,950 2017-02-07
Vxworks MEDIUM 5.8
CVE-2015-3963

Wind River VxWorks before 5.5.1, 6.5.x through 6.7.x before 6.7.1.1, 6.8.x before 6.8.3, 6.9.x before 6.9.4.4, and 7.x before 7 ipnet_coreip 1.2.2.0,…

Fix: 6.7.1.1 / 6.8.3+
Fix from $1,600 2015-08-04
Vxworks HIGH 10.0
CVE-2013-0714EPSS 6%

IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of service (daem…

Mitigation only
Fix from $1,950 2013-03-20
Vxworks HIGH 7.8
CVE-2013-0711

IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to cause a denial of service (daemon outage) via a crafted a…

Mitigation only
Fix from $1,950 2013-03-20
Vxworks MEDIUM 6.8
CVE-2013-0712

IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a…

Mitigation only
Fix from $1,600 2013-03-20