CVE-2026-105164
- EPSS 0.54%
- Veröffentlicht 04.10.2026 22:00:13
- Zuletzt bearbeitet 06.10.2026 15:04:52
A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read. Remote exploitation of the attack is possible. Th...
CVE-2026-82480
- EPSS 0.22%
- Veröffentlicht 30.08.2026 05:30:09
- Zuletzt bearbeitet 01.09.2026 20:48:22
A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the ar...
CVE-2026-82479
- EPSS 0.25%
- Veröffentlicht 30.08.2026 05:00:09
- Zuletzt bearbeitet 01.09.2026 20:48:22
A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The atta...
CVE-2026-67979
- EPSS 0.16%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:57
Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.
CVE-2026-67972
- EPSS 0.26%
- Veröffentlicht 03.08.2026 21:16:41
- Zuletzt bearbeitet 31.08.2026 19:33:57
An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure.
CVE-2026-67969
- EPSS 0.22%
- Veröffentlicht 03.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:57
An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.
CVE-2026-67970
- EPSS 0.23%
- Veröffentlicht 03.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:57
Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.
CVE-2026-67973
- EPSS 0.15%
- Veröffentlicht 03.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:57
An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.
CVE-2026-67974
- EPSS 0.3%
- Veröffentlicht 03.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:57
A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.
CVE-2026-67975
- EPSS 0.21%
- Veröffentlicht 03.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 19:33:57
Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.