Vulnerability index

Browse CVEs

168 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2026-0849 Malformed ATAES132A responses with an oversized length field overflow a 52-byte stack buffer in the Zephyr crypto driver, allowing a compromised devi… Zephyr Patch available Fix from $1,6002026-03-16 CRITICAL 9.8 CVE-2026-1678 dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cached size becomes incorrect, a… Zephyr after 4.3.0 Fix from $2,3002026-03-05 HIGH 7.6 CVE-2025-10458 Parameters are not validated or sanitized, and are later used in various internal operations. Zephyr after 4.1.0 Fix from $1,9502025-09-19 MEDIUM 6.5 CVE-2025-7403 Unsafe handling in bt_conn_tx_processor causes a use-after-free, resulting in a write-before-zero. The written 4 bytes are attacker-controlled, enabl… Zephyr after 4.1.0 Fix from $1,6002025-09-19 HIGH 8.1 CVE-2025-10457 The function responsible for handling BLE connection responses does not verify whether a response is expected—that is, whether the device has initiat… Zephyr after 4.1.0 Fix from $1,9502025-09-19 MEDIUM 6.5 CVE-2025-10456 A vulnerability was identified in the handling of Bluetooth Low Energy (BLE) fixed channels (such as SMP or ATT). Specifically, an attacker could exp… Zephyr after 4.1.0 Fix from $1,6002025-09-19 HIGH 7.5 CVE-2025-2962 A denial-of-service issue in the dns implemenation could cause an infinite loop. Zephyr after 4.1.0 Fix from $1,9502025-06-24 CRITICAL 9.1 CVE-2025-1675 The function dns_copy_qname in dns_pack.c performs performs a memcpy operation with an untrusted field and does not check if the source buffer is lar… Zephyr after 4.0.0 Fix from $2,3002025-02-25 HIGH 8.2 CVE-2025-1674 A lack of input validation allows for out of bounds reads caused by malicious or malformed packets. Zephyr after 4.0 Fix from $1,9502025-02-25 HIGH 8.2 CVE-2025-1673 A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of service) or an incorrect compu… Zephyr after 4.0 Fix from $1,9502025-02-25 HIGH 7.5 CVE-2024-10395 No proper validation of the length of user input in http_server_get_content_type_from_extension. Zephyr after 3.7.0 Fix from $1,9502025-02-03 MEDIUM 6.5 CVE-2024-8798 No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c. Zephyr after 3.7.0 Fix from $1,6002024-12-16 HIGH 8.4 CVE-2024-11263 When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata sectio… Zephyr after 3.7.0 Fix from $1,9502024-11-15 MEDIUM 6.5 CVE-2024-6444 No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c. Zephyr after 3.6.0 Fix from $1,6002024-10-04 MEDIUM 6.5 CVE-2024-6443 In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty. Zephyr after 3.6.0 Fix from $1,6002024-10-04 MEDIUM 6.5 CVE-2024-6442 In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow. Zephyr after 3.6.0 Fix from $1,6002024-10-04 MEDIUM 6.5 CVE-2024-6259 BT: HCI: adv_ext_report Improper discarding in adv_ext_report Zephyr after 3.6.0 Fix from $1,6002024-09-13 MEDIUM 6.5 CVE-2024-5931 BT: Unchecked user input in bap_broadcast_assistant Zephyr after 3.6.0 Fix from $1,6002024-09-13 MEDIUM 6.5 CVE-2024-6135 BT:Classic: Multiple missing buf length checks Zephyr after 3.6.0 Fix from $1,6002024-09-13 MEDIUM 6.5 CVE-2024-6137 BT: Classic: SDP OOB access in get_att_search_list Zephyr after 3.6.0 Fix from $1,6002024-09-13 MEDIUM 6.5 CVE-2024-5754 BT: Encryption procedure host vulnerability Zephyr 3.6.0+ Fix from $1,6002024-09-13 MEDIUM 6.5 CVE-2024-6258 BT: Missing length checks of net_buf in rfcomm_handle_data Zephyr 3.6.0+ Fix from $1,6002024-09-13 MEDIUM 6.5 CVE-2024-4785 BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero Zephyr 3.7.0+ Fix from $1,6002024-08-19 MEDIUM 6.5 CVE-2024-3332 A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device Zephyr after 3.6.0 Fix from $1,6002024-07-03 MEDIUM 6.5 CVE-2024-3077 An malicious BLE device can crash BLE victim device by sending malformed gatt packet Zephyr after 3.6.0 Fix from $1,6002024-03-29 HIGH 7.5 CVE-2023-7060 Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the desti… Zephyr 3.6.0+ Fix from $1,9502024-03-15 CRITICAL 9.8 CVE-2023-6881 Possible buffer overflow in is_mount_point Zephyr after 3.5.0 Fix from $2,3002024-02-29 CRITICAL 9.1 CVE-2024-1638 The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write … Zephyr after 3.5.0 Fix from $2,3002024-02-19 CRITICAL 9.8 CVE-2023-6249 Signed to unsigned conversion esp32_ipm_send Zephyr 3.5.0+ Fix from $2,3002024-02-18 CRITICAL 9.8 CVE-2023-5779 can: out of bounds in remove_rx_filter function Zephyr after 3.5.0 Fix from $2,3002024-02-18