Eclipse

Threadx

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 06.04.2025 19:15:41
  • Zuletzt bearbeitet 31.07.2025 16:34:08

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length in one...

  • EPSS 0.05%
  • Veröffentlicht 06.04.2025 19:15:41
  • Zuletzt bearbeitet 31.07.2025 16:31:39

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resulting in the...

  • EPSS 0.05%
  • Veröffentlicht 06.04.2025 18:50:42
  • Zuletzt bearbeitet 31.07.2025 16:34:14

In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content...

  • EPSS 0.13%
  • Veröffentlicht 21.02.2025 09:15:10
  • Zuletzt bearbeitet 31.07.2025 16:33:10

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length smalle...

  • EPSS 0.13%
  • Veröffentlicht 21.02.2025 09:15:09
  • Zuletzt bearbeitet 31.07.2025 16:33:00

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length in one...

  • EPSS 0.13%
  • Veröffentlicht 21.02.2025 08:15:28
  • Zuletzt bearbeitet 31.07.2025 16:32:38

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resulting in the...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 26.03.2024 16:15:13
  • Zuletzt bearbeitet 13.02.2025 18:17:52

In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. This could lead to integer wraparound, ...

  • EPSS 0.08%
  • Veröffentlicht 26.03.2024 16:15:13
  • Zuletzt bearbeitet 13.02.2025 18:17:52

In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. The affected file was ports/xtensa/xcc/src/tx_clib_lock.c