VendorsApachenuttxall versions
Vulnerabilities

Apache Software Foundation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2021-26461
malloc, realloc and memalign implementations are vulnerable to integer wrap-arounds
Published 2021-06-21 · Modified
9.8EPSS 0.050
CVE-2020-17529
Apache NuttX (incubating) Out of Bound Write from invalid fragmentation offset value specified in the IP header
Published 2020-12-09 · Modified
9.8EPSS 0.029
CVE-2020-1939
The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs. One of these, ftpd, had a NULL pointer dereference bug. The NuttX RTOS itself is not affected. Users of the optional apps repository are affected only if they have enabled ftpd. Versions 6.15 to 8.2 are affected.
Published 2020-05-12 · Modified
9.8EPSS 0.025
CVE-2025-35003
Apache NuttX RTOS: NuttX Bluetooth Stack HCI and UART DoS/RCE Vulnerabilities.
Published 2025-05-26 · Analyzed
9.8EPSS 0.015
CVE-2025-47868
Apache NuttX RTOS: tools/bdf-converter.: tools/bdf-converter: Fix loop termination condition.
Published 2025-06-16 · Analyzed
9.8EPSS 0.007
CVE-2025-47869
Apache NuttX RTOS: examples/xmlrpc: Fix calls buffers size.
Published 2025-06-16 · Analyzed
9.8EPSS 0.007
CVE-2020-17528
Apache NuttX (incubating) Out of Bound Write from invalid TCP Urgent length
Published 2020-12-09 · Modified
9.1EPSS 0.032
CVE-2025-48769
Apache NuttX RTOS: fs/vfs/fs_rename: use after free
Published 2026-01-01 · Analyzed
8.1EPSS 0.017
CVE-2025-48768
Apache NuttX RTOS: fs/inode: fs_inoderemove root inode removal
Published 2026-01-01 · Analyzed
6.5EPSS 0.008