Product:

Zephyr

(Zephyrproject)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 105
Date Id Summary Products Score Patch Annotated
2024-10-04 CVE-2024-6442 In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow. Zephyr 6.5
2024-10-04 CVE-2024-6444 No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c. Zephyr 6.5
2024-10-04 CVE-2024-6443 In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty. Zephyr 6.5
2024-09-13 CVE-2024-5754 BT: Encryption procedure host vulnerability Zephyr 6.5
2024-09-13 CVE-2024-6258 BT: Missing length checks of net_buf in rfcomm_handle_data Zephyr 6.5
2024-09-13 CVE-2024-5931 BT: Unchecked user input in bap_broadcast_assistant Zephyr 6.5
2024-09-13 CVE-2024-6135 BT:Classic: Multiple missing buf length checks Zephyr 6.5
2024-09-13 CVE-2024-6137 BT: Classic: SDP OOB access in get_att_search_list Zephyr 6.5
2024-09-13 CVE-2024-6259 BT: HCI: adv_ext_report Improper discarding in adv_ext_report Zephyr 6.5
2021-05-25 CVE-2020-10065 Missing Size Checks in Bluetooth HCI over SPI. Zephyr versions >= v1.14.2, >= v2.2.0 contain Improper Handling of Length Parameter Inconsistency (CWE-130). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hg2w-62p6-g67c Zephyr 8.8