Vulnerabilities > Zephyrproject > Zephyr > 1.14.1

DATE CVE VULNERABILITY TITLE RISK
2021-05-25 CVE-2020-13600 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
Malformed SPI in response for eswifi can corrupt kernel memory.
low complexity
zephyrproject CWE-787
7.6
2021-05-25 CVE-2020-13601 Out-of-bounds Read vulnerability in Zephyrproject Zephyr
Possible read out of bounds in dns read.
network
low complexity
zephyrproject CWE-125
critical
9.8
2021-05-25 CVE-2020-13602 Infinite Loop vulnerability in Zephyrproject Zephyr
Remote Denial of Service in LwM2M do_write_op_tlv.
local
low complexity
zephyrproject CWE-835
5.5
2021-05-25 CVE-2020-13603 Integer Overflow or Wraparound vulnerability in Zephyrproject Zephyr
Integer Overflow in memory allocating functions.
local
low complexity
zephyrproject CWE-190
7.8
2020-06-05 CVE-2020-10071 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
The Zephyr MQTT parsing code performs insufficient checking of the length field on publish messages, allowing a buffer overflow and potentially remote code execution.
network
low complexity
zephyrproject CWE-120
critical
9.8
2020-06-05 CVE-2020-10070 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
In the Zephyr Project MQTT code, improper bounds checking can result in memory corruption and possibly remote code execution.
network
low complexity
zephyrproject CWE-120
critical
9.8
2020-06-05 CVE-2020-10063 Integer Overflow or Wraparound vulnerability in Zephyrproject Zephyr
A remote adversary with the ability to send arbitrary CoAP packets to be parsed by Zephyr is able to cause a denial of service.
network
low complexity
zephyrproject CWE-190
7.5
2020-06-05 CVE-2020-10062 Off-by-one Error vulnerability in Zephyrproject Zephyr
An off-by-one error in the Zephyr project MQTT packet length decoder can result in memory corruption and possible remote code execution.
network
low complexity
zephyrproject CWE-193
critical
9.8
2020-05-11 CVE-2020-10067 Integer Overflow or Wraparound vulnerability in Zephyrproject Zephyr 1.14.1/2.1.0
A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handlers.
local
low complexity
zephyrproject CWE-190
7.8
2020-05-11 CVE-2020-10023 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr 1.14.1/2.1.0
The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause a memory corruption, resulting in denial of service or possibly code execution within the Zephyr kernel.
low complexity
zephyrproject CWE-120
6.8