CVE-2020-27634
- EPSS 1.72%
- Veröffentlicht 10.10.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 05:21:33
In Contiki 4.5, TCP ISNs are improperly random.
CVE-2023-37459
- EPSS 0.39%
- Veröffentlicht 15.09.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:11:44
Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when a packet is received, the Contiki-NG network stack attempts to start the periodic TCP timer if it is a TCP packet with the SYN flag set. But the impleme...
CVE-2023-37281
- EPSS 0.39%
- Veröffentlicht 15.09.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:11:23
Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when processing the various IPv6 header fields during IPHC header decompression, Contiki-NG confirms the received packet buffer contains enough data as neede...
CVE-2023-34101
- EPSS 0.51%
- Veröffentlicht 14.06.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:06:32
Contiki-NG is an operating system for internet of things devices. In version 4.8 and prior, when processing ICMP DAO packets in the `dao_input_storing` function, the Contiki-NG OS does not verify that the packet buffer is big enough to contain the by...
CVE-2023-34100
- EPSS 0.44%
- Veröffentlicht 09.06.2023 18:15:09
- Zuletzt bearbeitet 21.11.2024 08:06:32
Contiki-NG is an open-source, cross-platform operating system for IoT devices. When reading the TCP MSS option value from an incoming packet, the Contiki-NG OS does not verify that certain buffer indices to read from are within the bounds of the IPv6...
CVE-2023-31129
- EPSS 0.64%
- Veröffentlicht 08.05.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 08:01:27
The Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message handling code for IPv6 router solicitiations. Contiki-NG contains an implementation of IPv6 Neighbor Discovery (ND) in the module `os...
CVE-2023-30546
- EPSS 0.64%
- Veröffentlicht 26.04.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:00:23
Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope database management system in the Contiki-NG operating system in versions 4.8 and prior. The problem exists in the Contiki File Sys...
CVE-2023-28116
- EPSS 0.69%
- Veröffentlicht 17.03.2023 22:15:11
- Zuletzt bearbeitet 21.11.2024 07:54:26
Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an out-of-bounds write can occur in the BLE L2CAP module of the Contiki-NG operating system. The network stack of Contiki-...
CVE-2023-23609
- EPSS 0.35%
- Veröffentlicht 26.01.2023 21:18:14
- Zuletzt bearbeitet 21.11.2024 07:46:31
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to and including 4.8 are vulnerable to an out-of-bounds write that can occur in the BLE-L2CAP module. The Bluetooth Low Energy - Logical Lin...
CVE-2022-41972
- EPSS 0.21%
- Veröffentlicht 16.12.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:24:11
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 contain a NULL Pointer Dereference in BLE L2CAP module. The Contiki-NG operating system for IoT devices contains a Bluetooth Low Ener...