VendorsApachenimbleany version
Vulnerabilities

Apache Nimble any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-45813
Apache NimBLE: Incorrect data validation in BASS add/modify source operation
Published 2026-07-24 · Analyzed
8.8EPSS 0.004
CVE-2025-62235
Apache Mynewt NimBLE: Incorrect handling of SMP Security Request could lead to undesirable pairing
Published 2026-01-10 · Analyzed
8.1EPSS 0.004
CVE-2024-24746
Apache NimBLE: Denial of service in NimBLE Bluetooth stack
Published 2024-04-06 · Analyzed
7.5EPSS 0.014
CVE-2024-51569
Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in Number of Completed Packets HCI event handler
Published 2024-11-26 · Analyzed
7.5EPSS 0.012
CVE-2025-53477
Apache Mynewt NimBLE: NULL Pointer Dereference in NimBLE host HCI layer
Published 2026-01-10 · Analyzed
7.5EPSS 0.008
CVE-2026-45816
Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request
Published 2026-07-24 · Analyzed
7.5EPSS 0.006
CVE-2026-45815
Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler
Published 2026-07-24 · Analyzed
7.5EPSS 0.006
CVE-2026-45811
Apache NimBLE: Buffer overflow in socket HCI transport
Published 2026-07-24 · Analyzed
7.5EPSS 0.003
CVE-2025-52435
Apache Mynewt NimBLE: Invalid error handling in pause encryption procedure in NimBLE controller
Published 2026-01-10 · Analyzed
7.5EPSS 0.002
CVE-2026-45812
Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
Published 2026-07-24 · Analyzed
6.5EPSS 0.004
CVE-2024-47248
Apache NimBLE: Buffer overflow in NimBLE MESH Bluetooth stack
Published 2024-11-26 · Analyzed
6.3EPSS 0.007
CVE-2026-46452
Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure
Published 2026-07-24 · Analyzed
5.3EPSS 0.006
CVE-2024-47250
Apache NimBLE: Lack of input validation in HCI advertising report could lead to potential out-of-bound access
Published 2024-11-26 · Analyzed
5.0EPSS 0.007
CVE-2024-47249
Apache NimBLE: Lack of input sanitization leading to out-of-bound reads in multiple advertisement handler
Published 2024-11-26 · Analyzed
5.0EPSS 0.006
CVE-2025-53470
Apache Mynewt NimBLE: Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver
Published 2026-01-10 · Analyzed
3.1EPSS 0.003