Vulnerabilities > Zephyrproject > Zephyr > 2.87.0

DATE CVE VULNERABILITY TITLE RISK
2024-12-16 CVE-2024-8798 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.
low complexity
zephyrproject CWE-787
6.5
2024-11-15 CVE-2024-11263 Unspecified vulnerability in Zephyrproject Zephyr
When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the linker to relax accesses to global symbols.
local
low complexity
zephyrproject
8.4
2024-08-19 CVE-2024-4785 Divide By Zero vulnerability in Zephyrproject Zephyr
BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
low complexity
zephyrproject CWE-369
6.5
2024-07-03 CVE-2024-3332 NULL Pointer Dereference vulnerability in Zephyrproject Zephyr
A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device
low complexity
zephyrproject CWE-476
6.5
2024-03-29 CVE-2024-3077 Integer Underflow (Wrap or Wraparound) vulnerability in Zephyrproject Zephyr
An malicious BLE device can crash BLE victim device by sending malformed gatt packet
low complexity
zephyrproject CWE-191
6.5
2024-03-15 CVE-2023-7060 Unspecified vulnerability in Zephyrproject Zephyr
Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the destination address.
network
low complexity
zephyrproject
7.5
2024-02-29 CVE-2023-6881 Classic Buffer Overflow vulnerability in Zephyrproject Zephyr
Possible buffer overflow in is_mount_point
network
low complexity
zephyrproject CWE-120
critical
9.8
2024-02-19 CVE-2024-1638 Unspecified vulnerability in Zephyrproject Zephyr
The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write permission with LE Secure Connection encryption.
network
low complexity
zephyrproject
critical
9.1
2024-02-18 CVE-2023-5779 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
can: out of bounds in remove_rx_filter function
network
low complexity
zephyrproject CWE-787
critical
9.8
2024-02-18 CVE-2023-6249 Incorrect Type Conversion or Cast vulnerability in Zephyrproject Zephyr
Signed to unsigned conversion esp32_ipm_send
network
low complexity
zephyrproject CWE-704
critical
9.8