Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.8
CVE-2026-0849
Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised devi…
Zephyr
Patch available
CRITICAL 9.8
CVE-2026-1678
dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, a…
Zephyr
after 4.3.0
HIGH 7.6
CVE-2025-10458
Parameters are not validated or sanitized, and are later used in various internal operations.
Zephyr
after 4.1.0
MEDIUM 6.5
CVE-2025-7403
Unsafe handling in bt_conn_tx_processor causes a use-after-free, resulting in a write-before-zero. The written 4 bytes are attacker-controlled, enabl…
Zephyr
after 4.1.0
HIGH 8.1
CVE-2025-10457
The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiat…
Zephyr
after 4.1.0
MEDIUM 6.5
CVE-2025-10456
A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exp…
Zephyr
after 4.1.0
HIGH 7.5
CVE-2025-2962
A denial-of-service issue in the dns implemenation could cause an infinite loop.
Zephyr
after 4.1.0
CRITICAL 9.1
CVE-2025-1675
The function dns_copy_qname in dns_pack.c performs performs a memcpy operation with an untrusted field and does not check if the source buffer is lar…
Zephyr
after 4.0.0
HIGH 8.2
CVE-2025-1674
A lack of input validation allows for out of bounds reads caused by malicious or malformed packets.
Zephyr
after 4.0
HIGH 8.2
CVE-2025-1673
A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of service) or an incorrect compu…
Zephyr
after 4.0
HIGH 7.5
CVE-2024-10395
No proper validation of the length of user input in http_server_get_content_type_from_extension.
Zephyr
after 3.7.0
MEDIUM 6.5
CVE-2024-8798
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.
Zephyr
after 3.7.0
HIGH 8.4
CVE-2024-11263
When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata sectio…
Zephyr
after 3.7.0
MEDIUM 6.5
CVE-2024-6444
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.
Zephyr
after 3.6.0
MEDIUM 6.5
CVE-2024-6443
In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.
Zephyr
after 3.6.0
MEDIUM 6.5
CVE-2024-6442
In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.
Zephyr
after 3.6.0
MEDIUM 6.5
CVE-2024-6259
BT: HCI: adv_ext_report Improper discarding in adv_ext_report
Zephyr
after 3.6.0
MEDIUM 6.5
CVE-2024-5931
BT: Unchecked user input in bap_broadcast_assistant
Zephyr
after 3.6.0
MEDIUM 6.5
CVE-2024-6135
BT:Classic: Multiple missing buf length checks
Zephyr
after 3.6.0
MEDIUM 6.5
CVE-2024-6137
BT: Classic: SDP OOB access in get_att_search_list
Zephyr
after 3.6.0
MEDIUM 6.5
CVE-2024-5754
BT: Encryption procedure host vulnerability
Zephyr
3.6.0+
MEDIUM 6.5
CVE-2024-6258
BT: Missing length checks of net_buf in rfcomm_handle_data
Zephyr
3.6.0+
MEDIUM 6.5
CVE-2024-4785
BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
Zephyr
3.7.0+
MEDIUM 6.5
CVE-2024-3332
A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device
Zephyr
after 3.6.0
MEDIUM 6.5
CVE-2024-3077
An malicious BLE device can crash BLE victim device by sending malformed gatt packet
Zephyr
after 3.6.0
HIGH 7.5
CVE-2023-7060
Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the desti…
Zephyr
3.6.0+
CRITICAL 9.8
CVE-2023-6881
Possible buffer overflow in is_mount_point
Zephyr
after 3.5.0
CRITICAL 9.1
CVE-2024-1638
The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write …
Zephyr
after 3.5.0
CRITICAL 9.8
CVE-2023-6249
Signed to unsigned conversion esp32_ipm_send
Zephyr
3.5.0+
CRITICAL 9.8
CVE-2023-5779
can: out of bounds in remove_rx_filter function
Zephyr
after 3.5.0