Vulnerabilities > Zephyrproject > Zephyr > 2.1.0

DATE CVE VULNERABILITY TITLE RISK
2020-05-11 CVE-2020-10023 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr 1.14.1/2.1.0
The shell subsystem contains a buffer overflow, whereby an adversary with physical access to the device is able to cause a memory corruption, resulting in denial of service or possibly code execution within the Zephyr kernel.
local
low complexity
zephyrproject CWE-120
4.6
2020-05-11 CVE-2020-10022 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr 2.1.0/2.2.0
A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS.
network
low complexity
zephyrproject CWE-120
7.5
2020-05-11 CVE-2020-10021 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-ZEP-026 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions.
local
low complexity
zephyrproject CWE-787
4.6
2020-05-11 CVE-2020-10019 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size.
local
low complexity
zephyrproject CWE-120
4.6