Vulnerabilities > Zephyrproject > Zephyr > High

DATE CVE VULNERABILITY TITLE RISK
2021-05-25 CVE-2020-13603 Integer Overflow or Wraparound vulnerability in Zephyrproject Zephyr
Integer Overflow in memory allocating functions.
local
low complexity
zephyrproject CWE-190
7.8
2021-05-25 CVE-2021-3320 Type Confusion vulnerability in Zephyrproject Zephyr
Type Confusion in 802154 ACK Frames Handling.
network
low complexity
zephyrproject CWE-843
7.5
2020-06-05 CVE-2020-10063 Integer Overflow or Wraparound vulnerability in Zephyrproject Zephyr
A remote adversary with the ability to send arbitrary CoAP packets to be parsed by Zephyr is able to cause a denial of service.
network
low complexity
zephyrproject CWE-190
7.5
2020-06-05 CVE-2020-10061 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
Improper handling of the full-buffer case in the Zephyr Bluetooth implementation can result in memory corruption.
low complexity
zephyrproject CWE-787
8.8
2020-05-11 CVE-2020-10067 Integer Overflow or Wraparound vulnerability in Zephyrproject Zephyr 1.14.1/2.1.0
A malicious userspace application can cause a integer overflow and bypass security checks performed by system call handlers.
local
low complexity
zephyrproject CWE-190
7.8
2020-05-11 CVE-2020-10058 Improper Input Validation vulnerability in Zephyrproject Zephyr 2.1.0
Multiple syscalls in the Kscan subsystem perform insufficient argument validation, allowing code executing in userspace to potentially gain elevated privileges.
local
low complexity
zephyrproject CWE-20
7.8
2020-05-11 CVE-2020-10028 Improper Input Validation vulnerability in Zephyrproject Zephyr 1.14.0/2.1.0
Multiple syscalls with insufficient argument validation See NCC-ZEP-006 This issue affects: zephyrproject-rtos zephyr version 1.14.0 and later versions.
local
low complexity
zephyrproject CWE-20
7.8
2020-05-11 CVE-2020-10027 Incorrect Comparison vulnerability in Zephyrproject Zephyr 1.14.0/2.1.0
An attacker who has obtained code execution within a user thread is able to elevate privileges to that of the kernel.
local
low complexity
zephyrproject CWE-697
7.8
2020-05-11 CVE-2020-10024 Incorrect Comparison vulnerability in Zephyrproject Zephyr 1.14.2/2.1.0
The arm platform-specific code uses a signed integer comparison when validating system call numbers.
local
low complexity
zephyrproject CWE-697
7.8
2020-05-11 CVE-2020-10021 Out-of-bounds Write vulnerability in Zephyrproject Zephyr
Out-of-bounds Write in the USB Mass Storage memoryWrite handler with unaligned Sizes See NCC-ZEP-024, NCC-ZEP-025, NCC-ZEP-026 This issue affects: zephyrproject-rtos zephyr version 1.14.1 and later versions.
local
low complexity
zephyrproject CWE-787
7.8