Vulnerabilities > Zephyrproject

DATE CVE VULNERABILITY TITLE RISK
2024-10-04 CVE-2024-6444 Out-of-bounds Write vulnerability in Zephyrproject Zephyr 3.2.01
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.
low complexity
zephyrproject CWE-787
6.5
2024-10-04 CVE-2024-6442 Out-of-bounds Write vulnerability in Zephyrproject Zephyr 3.2.01
In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.
low complexity
zephyrproject CWE-787
6.5
2024-10-04 CVE-2024-6443 Out-of-bounds Write vulnerability in Zephyrproject Zephyr 3.2.01
In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.
low complexity
zephyrproject CWE-787
6.5
2024-09-13 CVE-2024-6259 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
BT: HCI: adv_ext_report Improper discarding in adv_ext_report
low complexity
zephyrproject CWE-787
6.5
2024-09-13 CVE-2024-5931 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
BT: Unchecked user input in bap_broadcast_assistant
low complexity
zephyrproject CWE-787
6.5
2024-09-13 CVE-2024-6135 Divide By Zero vulnerability in Zephyrproject Zephyr
BT:Classic: Multiple missing buf length checks
low complexity
zephyrproject CWE-369
6.5
2024-09-13 CVE-2024-6137 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
BT: Classic: SDP OOB access in get_att_search_list
low complexity
zephyrproject CWE-787
6.5
2024-09-13 CVE-2024-5754 Unspecified vulnerability in Zephyrproject Zephyr
BT: Encryption procedure host vulnerability
low complexity
zephyrproject
6.5
2024-09-13 CVE-2024-6258 Integer Underflow (Wrap or Wraparound) vulnerability in Zephyrproject Zephyr
BT: Missing length checks of net_buf in rfcomm_handle_data
low complexity
zephyrproject CWE-191
6.5
2023-11-21 CVE-2023-5055 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
Possible variant of CVE-2021-3434 in function le_ecred_reconf_req.
network
low complexity
zephyrproject CWE-787
critical
9.8