Zephyrproject

Zephyr

106 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Published 04.08.2025 01:49:46
  • Last modified 18.08.2025 15:42:28

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is need...

  • EPSS 0.15%
  • Published 25.02.2025 08:15:30
  • Last modified 28.02.2025 01:30:32

The function dns_copy_qname in dns_pack.c performs performs a memcpy operation with an untrusted field and does not check if the source buffer is large enough to contain the copied data.

  • EPSS 0.13%
  • Published 25.02.2025 08:15:29
  • Last modified 28.02.2025 01:30:32

A lack of input validation allows for out of bounds reads caused by malicious or malformed packets.

  • EPSS 0.27%
  • Published 25.02.2025 07:15:18
  • Last modified 28.02.2025 01:30:32

A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of service) or an incorrect computation.

  • EPSS 0.24%
  • Published 16.12.2024 00:15:05
  • Last modified 17.09.2025 06:15:41

No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.

  • EPSS 0.04%
  • Published 15.11.2024 23:15:10
  • Last modified 03.02.2025 20:09:54

When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the linker to relax accesses to global symbols.

  • EPSS 0.07%
  • Published 04.10.2024 07:15:02
  • Last modified 13.11.2024 15:24:28

No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.

Exploit
  • EPSS 0.08%
  • Published 04.10.2024 06:15:05
  • Last modified 12.11.2024 19:29:43

In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.

  • EPSS 0.07%
  • Published 04.10.2024 06:15:04
  • Last modified 13.11.2024 16:04:42

In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.

Exploit
  • EPSS 0.08%
  • Published 13.09.2024 21:15:10
  • Last modified 17.09.2025 06:15:41

BT: HCI: adv_ext_report Improper discarding in adv_ext_report