Product:

Zephyr

(Zephyrproject)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 91
Date Id Summary Products Score Patch Annotated
2023-10-13 CVE-2023-4263 Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver Zephyr 8.8
2023-10-13 CVE-2023-4257 Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows. Zephyr 9.8
2023-10-25 CVE-2023-5753 Potential buffer overflows in the Bluetooth subsystem due to asserts being disabled in /subsys/bluetooth/host/hci_core.c Zephyr 8.8
2023-10-26 CVE-2023-5139 Potential buffer overflow vulnerability at the following location in the Zephyr STM32 Crypto driver Zephyr 7.8
2023-11-21 CVE-2023-4424 An malicious BLE device can cause buffer overflow by sending malformed advertising packet BLE device using Zephyr OS, leading to DoS or potential RCE on the victim BLE device. Zephyr 8.8
2023-11-21 CVE-2023-5055 Possible variant of CVE-2021-3434 in function le_ecred_reconf_req. Zephyr 9.8
2024-10-04 CVE-2024-6442 In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow. Zephyr 6.5
2024-10-04 CVE-2024-6444 No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c. Zephyr 6.5
2024-10-04 CVE-2024-6443 In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty. Zephyr 6.5
2024-09-13 CVE-2024-5754 BT: Encryption procedure host vulnerability Zephyr 6.5