Vulnerability index

Browse CVEs

168 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zephyr CRITICAL 9.8
CVE-2020-10070

In the Zephyr Project MQTT code, improper bounds checking can result in memory corruption and possibly remote code execution. NCC-ZEP-031 This issue …

Fix: after 2.2.0
Fix from $2,300 2020-06-05
Zephyr HIGH 8.8
CVE-2020-10061

Improper handling of the full-buffer case in the Zephyr Bluetooth implementation can result in memory corruption. This issue affects: zephyrproject-r…

Fix: 1.14.0 / 2.2.0+
Fix from $1,950 2020-06-05
Zephyr HIGH 7.5
CVE-2020-10063

A remote adversary with the ability to send arbitrary CoAP packets to be parsed by Zephyr is able to cause a denial of service. This issue affects: z…

Fix: after 2.2.0
Fix from $1,950 2020-06-05
Zephyr MEDIUM 6.5
CVE-2020-10068

In the Zephyr project Bluetooth subsystem, certain duplicate and back-to-back packets can cause incorrect behavior, resulting in a denial of service.…

Fix: 1.14.0 / 2.2.0+
Fix from $1,600 2020-06-05
Zephyr HIGH 7.8
CVE-2020-10067

A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handlers. The impact would depend …

Patch available
Fix from $1,950 2020-05-11
Zephyr MEDIUM 6.5
CVE-2020-10060

In updatehub_probe, right after JSON parsing is complete, objects\[1] is accessed from the output structure in two different places. If the JSON cont…

Fix: 2.4.0+
Fix from $1,600 2020-05-11
Zephyr CRITICAL 9.8
CVE-2020-10022

A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This could result in a denial of s…

Patch available
Fix from $2,300 2020-05-11
Zephyr HIGH 7.8
CVE-2020-10019

USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size. This could be used by a maliciou…

Fix: 1.14.2+
Fix from $1,950 2020-05-11
Zephyr HIGH 7.8
CVE-2020-10021

Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-ZEP-026 This issue affects: ze…

Fix: 2.2.0+
Fix from $1,950 2020-05-11
Zephyr HIGH 7.8
CVE-2020-10024

The arm platform-specific code uses a signed integer comparison when validating system call numbers. An attacker who has obtained code execution with…

Patch available
Fix from $1,950 2020-05-11
Zephyr HIGH 7.8
CVE-2020-10027

An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel. See NCC-ZEP-001 This issue affe…

Patch available
Fix from $1,950 2020-05-11
Zephyr HIGH 7.8
CVE-2020-10028

Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versio…

Patch available
Fix from $1,950 2020-05-11
Zephyr HIGH 7.8
CVE-2020-10058

Multiple syscalls in the Kscan subsystem perform insufficient argument validation, allowing code executing in userspace to potentially gain elevated …

Patch available
Fix from $1,950 2020-05-11
Zephyr MEDIUM 6.8
CVE-2020-10023

The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause a memory corruption, resulti…

Patch available
Fix from $1,600 2020-05-11
Zephyr HIGH 7.8
CVE-2017-14201

Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, and possibly remote code execut…

Fix: 1.14.0+
Fix from $1,950 2019-08-29
Zephyr HIGH 7.8
CVE-2017-14202

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet conn…

Fix: 1.14.0+
Fix from $1,950 2019-08-29
Zephyr CRITICAL 9.8
CVE-2017-14199

A buffer overflow has been found in the Zephyr Project's getaddrinfo() implementation in 1.9.0 and 1.10.0.

Patch available
Fix from $2,300 2019-04-12
Zephyr CRITICAL 9.8
CVE-2018-1000800

zephyr-rtos version 1.12.0 contains a NULL base pointer reference vulnerability in sys_ring_buf_put(), sys_ring_buf_get() that can result in CPU Page…

No fix yet
Fix from $2,300 2018-09-06