CVEs (163)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
No proper validation of the length of user input in http_server_get_content_type_from_extension. |
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c. |
When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the linker to relax accesses to global symbols. |
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c. |
In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty. |
In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow. |
BT: HCI: adv_ext_report Improper discarding in adv_ext_report |
BT: Classic: SDP OOB access in get_att_search_list |
BT:Classic: Multiple missing buf length checks |
BT: Unchecked user input in bap_broadcast_assistant |
BT: Missing length checks of net_buf in rfcomm_handle_data |
BT: Encryption procedure host vulnerability |
BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero |
A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device |
An malicious BLE device can crash BLE victim device by sending malformed gatt packet |
Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the destination address. |
Possible buffer overflow in is_mount_point |
The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write permission with LE Secure Connection encryption. If set, requires that...Show more |
Signed to unsigned conversion esp32_ipm_send |
can: out of bounds in remove_rx_filter function |