Vulnerabilities > Zephyrproject > Zephyr > 1.14.3

DATE CVE VULNERABILITY TITLE RISK
2022-06-28 CVE-2021-3430 Reachable Assertion vulnerability in Zephyrproject Zephyr
Assertion reachable with repeated LL_CONNECTION_PARAM_REQ.
network
low complexity
zephyrproject CWE-617
7.5
2022-06-28 CVE-2021-3432 Divide By Zero vulnerability in Zephyrproject Zephyr
Invalid interval in CONNECT_IND leads to Division by Zero.
network
low complexity
zephyrproject CWE-369
7.5
2021-10-05 CVE-2021-3510 Unspecified vulnerability in Zephyrproject Zephyr
Zephyr JSON decoder incorrectly decodes array of array.
network
low complexity
zephyrproject
7.5
2020-06-05 CVE-2020-10071 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
The Zephyr MQTT parsing code performs insufficient checking of the length field on publish messages, allowing a buffer overflow and potentially remote code execution.
network
low complexity
zephyrproject CWE-120
critical
9.8
2020-06-05 CVE-2020-10070 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
In the Zephyr Project MQTT code, improper bounds checking can result in memory corruption and possibly remote code execution.
network
low complexity
zephyrproject CWE-120
critical
9.8
2020-06-05 CVE-2020-10063 Integer Overflow or Wraparound vulnerability in Zephyrproject Zephyr
A remote adversary with the ability to send arbitrary CoAP packets to be parsed by Zephyr is able to cause a denial of service.
network
low complexity
zephyrproject CWE-190
7.5
2020-06-05 CVE-2020-10062 Off-by-one Error vulnerability in Zephyrproject Zephyr
An off-by-one error in the Zephyr project MQTT packet length decoder can result in memory corruption and possible remote code execution.
network
low complexity
zephyrproject CWE-193
critical
9.8