Ericsson

Codechecker

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 28.08.2026 12:57:50
  • Zuletzt bearbeitet 01.09.2026 21:07:58

CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store analysis runs can submit a hi...

  • EPSS 0.13%
  • Veröffentlicht 28.08.2026 12:46:57
  • Zuletzt bearbeitet 01.09.2026 21:07:58

CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r  was fixed by replacing unchecked strcpy() with a bounded safe_strcpy() helper. At ldlogger-tool-gcc.c:129 the destination passed to that helper is fullPath + 2, but the size passed dow...

  • EPSS 0.23%
  • Veröffentlicht 26.08.2026 06:48:06
  • Zuletzt bearbeitet 01.09.2026 21:07:58

The personal access token removal query selects from PersonalAccessTokenDB but filters on columns of Session, with no join between them. SQLAlchemy resolves that as an implicit cross join, so the filter does not constrain the delete to the calling us...

  • EPSS 0.45%
  • Veröffentlicht 24.04.2026 13:10:26
  • Zuletzt bearbeitet 27.04.2026 14:48:20

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls.  This bypass allows assigning arbi...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 28.10.2025 18:49:49
  • Zuletzt bearbeitet 08.10.2026 11:10:00

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger library, which is executed ...

  • EPSS 0.26%
  • Veröffentlicht 28.02.2025 13:15:27
  • Zuletzt bearbeitet 14.11.2025 15:29:28

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server contains an open redirect vulnerability due to missing protections against multiple slashes after the ...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 21.01.2025 15:15:13
  • Zuletzt bearbeitet 14.11.2025 15:30:12

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Cross-site request forgery allows an unauthenticated attacker to hijack the authentication of a logged in user, and use the web AP...

  • EPSS 39.12%
  • Veröffentlicht 06.11.2024 15:15:11
  • Zuletzt bearbeitet 14.11.2025 16:36:09

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser access to all API endpoints o...

  • EPSS 0.48%
  • Veröffentlicht 06.11.2024 15:15:11
  • Zuletzt bearbeitet 14.11.2025 17:24:08

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external service. The built-in root user up un...

Exploit
  • EPSS 0.73%
  • Veröffentlicht 24.06.2024 18:15:10
  • Zuletzt bearbeitet 21.11.2024 08:33:51

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the server endpoint of `CodeChecker store` are not properly sanitized. An attacker, using a path traversal at...