Vulnerabilities > Zephyrproject > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-06-05 CVE-2020-10062 Off-by-one Error vulnerability in Zephyrproject Zephyr
An off-by-one error in the Zephyr project MQTT packet length decoder can result in memory corruption and possible remote code execution.
network
low complexity
zephyrproject CWE-193
critical
9.8
2020-05-11 CVE-2020-10022 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr 2.1.0/2.2.0
A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS.
network
low complexity
zephyrproject CWE-120
critical
9.8
2019-04-12 CVE-2017-14199 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Zephyrproject Zephyr 1.10.0/1.9.0
A buffer overflow has been found in the Zephyr Project's getaddrinfo() implementation in 1.9.0 and 1.10.0.
network
low complexity
zephyrproject CWE-119
critical
9.8
2018-09-06 CVE-2018-1000800 NULL Pointer Dereference vulnerability in Zephyrproject Zephyr 1.12.0
zephyr-rtos version 1.12.0 contains a NULL base pointer reference vulnerability in sys_ring_buf_put(), sys_ring_buf_get() that can result in CPU Page Fault (error code 0x00000010).
network
low complexity
zephyrproject CWE-476
critical
9.8