Vulnerabilities > Zephyrproject > Zephyr > 1.6.0

DATE CVE VULNERABILITY TITLE RISK
2023-11-21 CVE-2023-5055 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
Possible variant of CVE-2021-3434 in function le_ecred_reconf_req.
network
low complexity
zephyrproject CWE-787
critical
9.8
2023-11-21 CVE-2023-4424 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
An malicious BLE device can cause buffer overflow by sending malformed advertising packet BLE device using Zephyr OS, leading to DoS or potential RCE on the victim BLE device.
low complexity
zephyrproject CWE-120
8.8
2023-10-26 CVE-2023-5139 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
Potential buffer overflow vulnerability at the following location in the Zephyr STM32 Crypto driver
local
low complexity
zephyrproject CWE-120
7.8
2023-10-13 CVE-2023-4263 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver
low complexity
zephyrproject CWE-120
8.8
2023-10-06 CVE-2023-3725 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem
network
low complexity
zephyrproject CWE-787
critical
9.8
2023-09-27 CVE-2023-4260 Off-by-one Error vulnerability in Zephyrproject Zephyr
Potential off-by-one buffer overflow vulnerability in the Zephyr fuse file system.
network
low complexity
zephyrproject CWE-193
critical
10.0
2023-09-27 CVE-2023-4262 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
Possible buffer overflow  in Zephyr mgmt subsystem when asserts are disabled
network
low complexity
zephyrproject CWE-120
critical
10.0
2023-09-27 CVE-2023-4264 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
Potential buffer overflow vulnerabilities n the Zephyr Bluetooth subsystem.
low complexity
zephyrproject CWE-120
critical
9.6
2023-09-26 CVE-2023-4259 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
Two potential buffer overflow vulnerabilities at the following locations in the Zephyr eS-WiFi driver source code.
low complexity
zephyrproject CWE-120
8.8
2023-09-25 CVE-2023-4258 Unspecified vulnerability in Zephyrproject Zephyr 1.14.1/1.6.0/2.0.0
In Bluetooth mesh implementation If provisionee has a public key that is sent OOB then during provisioning it can be sent back and will be accepted by provisionee.
low complexity
zephyrproject
6.5