Vulnerabilities > Zephyrproject > Zephyr
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-05-11 | CVE-2020-10019 | Classic Buffer Overflow vulnerability in Zephyrproject Zephyr USB DFU has a potential buffer overflow where the requested length (wLength) is not checked against the buffer size. | 7.8 |
2019-08-29 | CVE-2017-14202 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Zephyrproject Zephyr Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet connected user to cause a crash, possibly with arbitrary code execution. | 7.8 |
2019-08-29 | CVE-2017-14201 | Use After Free vulnerability in Zephyrproject Zephyr Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, and possibly remote code execution. | 7.8 |
2019-04-12 | CVE-2017-14199 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Zephyrproject Zephyr 1.10.0/1.9.0 A buffer overflow has been found in the Zephyr Project's getaddrinfo() implementation in 1.9.0 and 1.10.0. | 9.8 |
2018-09-06 | CVE-2018-1000800 | NULL Pointer Dereference vulnerability in Zephyrproject Zephyr 1.12.0 zephyr-rtos version 1.12.0 contains a NULL base pointer reference vulnerability in sys_ring_buf_put(), sys_ring_buf_get() that can result in CPU Page Fault (error code 0x00000010). | 9.8 |