VendorsZephyrprojectzephyrall versions
Vulnerabilities

Zephyrproject Zephyr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

189CVEs
CVE-2023-4260
Potential off-by-one buffer overflow vulnerability in the Zephyr FS subsystem
Published 2023-09-26 · Modified
10.0EPSS 0.008
CVE-2020-10071
Insufficient publish message length validation in MQTT
Published 2020-06-05 · Modified
9.8EPSS 0.034
CVE-2020-10062
Packet length decoding error in MQTT
Published 2020-06-05 · Modified
9.8EPSS 0.029
CVE-2020-10070
MQTT buffer overflow on receive buffer
Published 2020-06-05 · Modified
9.8EPSS 0.029
CVE-2020-10022
UpdateHub Module Copies a Variable-Size Hash String Into a Fixed-Size Array
Published 2020-05-11 · Modified
9.8EPSS 0.023
CVE-2021-3625
Buffer overflow in Zephyr USB DFU DNLOAD
Published 2021-10-05 · Modified
9.8EPSS 0.023
CVE-2017-14199
A buffer overflow has been found in the Zephyr Project's getaddrinfo() implementation in 1.9.0 and 1.10.0.
Published 2019-04-12 · Modified
9.8EPSS 0.017
CVE-2018-1000800
zephyr-rtos version 1.12.0 contains a NULL base pointer reference vulnerability in sys_ring_buf_put(), sys_ring_buf_get() that can result in CPU Page Fault (error code 0x00000010). This attack appear to be exploitable via a malicious application call the vulnerable kernel APIs (system sys_ring_buf_get() and sys_ring_buf_put).
Published 2018-09-06 · Modified
9.8EPSS 0.017
CVE-2023-3725
Potential buffer overflow vulnerability in the Zephyr CANbus subsystem
Published 2023-10-06 · Modified
9.8EPSS 0.011
CVE-2022-3806
Bluetooth HCI Error Handling Double Free
Published 2023-01-19 · Modified
9.8EPSS 0.010
CVE-2020-13601
Possible read out of bounds in dns read
Published 2021-05-24 · Modified
9.8EPSS 0.009
CVE-2021-3323
Integer Underflow in 6LoWPAN IPHC Header Uncompression in Zephyr
Published 2021-10-12 · Modified
9.8EPSS 0.009
CVE-2021-3319
DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses
Published 2021-10-05 · Modified
9.8EPSS 0.009
CVE-2023-4257
Unchecked user input length in the Zephyr WiFi shell module
Published 2023-10-13 · Modified
9.8EPSS 0.009
CVE-2026-5067
Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Key
Published 2026-06-09 · Analyzed
9.8EPSS 0.009
CVE-2020-10064
Improper Input Frame Validation in ieee802154 Processing
Published 2021-05-24 · Modified
9.8EPSS 0.008
CVE-2023-5055
L2CAP: Possible Stack based buffer overflow in le_ecred_reconf_req()
Published 2023-11-21 · Modified
9.8EPSS 0.008
CVE-2026-10666
Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`
Published 2026-07-12 · Analyzed
9.8EPSS 0.007
CVE-2022-2993
bt: host: Wrong key validation check
Published 2022-12-12 · Modified
9.8EPSS 0.006
CVE-2023-6749
Unchecked user input length in the Zephyr Settings Shell
Published 2024-02-18 · Analyzed
9.8EPSS 0.004
CVE-2023-6249
ipm: signed to unsigned conversion problem in esp32_ipm_send
Published 2024-02-18 · Analyzed
9.8EPSS 0.004
CVE-2023-6881
fs: fuse: buffer overflow vulnerability in the Zephyr FS
Published 2024-02-20 · Analyzed
9.8EPSS 0.004
CVE-2023-5779
can: out of bounds in remove_rx_filter function
Published 2024-02-18 · Analyzed
9.8EPSS 0.004
CVE-2026-1678
dns: memory‑safety issue in the DNS name parser
Published 2026-03-05 · Analyzed
9.8EPSS 0.004
CVE-2023-4264
Potential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystem
Published 2023-09-26 · Modified
9.6EPSS 0.009
CVE-2021-3329
DOS: Incorrect handling of the initial HCI ACL_MTU handshake packet leads to crash of bluetooth host layer
Published 2023-02-26 · Modified
9.6EPSS 0.006
CVE-2021-3966
Usb bluetooth device ACL read cb buffer overflow
Published 2023-01-11 · Modified
9.6EPSS 0.005
CVE-2023-0397
DoS: Invalid Initialization in le_read_buffer_size_complete
Published 2023-01-19 · Modified
9.6EPSS 0.005
CVE-2024-11263
arch: riscv: userspace: potential security risk when CONFIG_RISCV_GP=y
Published 2024-11-15 · Analyzed
9.3EPSS 0.002
CVE-2026-10672
Unterminated URI buffer causes out-of-bounds read in LwM2M firmware pull (Package URI)
Published 2026-07-14 · Analyzed
9.1EPSS 0.006
CVE-2025-1675
Out of bounds read in dns_copy_qname
Published 2025-02-25 · Analyzed
9.1EPSS 0.004
CVE-2024-1638
Bluetooth characteristic LESC security requirement not enforced without additional flags
Published 2024-02-19 · Analyzed
9.1EPSS 0.004
CVE-2023-5753
Potential buffer overflow vulnerabilities in the Zephyr Bluetooth subsystem
Published 2023-10-24 · Modified
8.8EPSS 0.009
CVE-2022-1041
Out-of-bound write vulnerability in the Bluetooth mesh core stack can be triggered during provisioning
Published 2022-07-26 · Modified
8.8EPSS 0.009
CVE-2022-1042
Out-of-bound write vulnerability in the Bluetooth mesh core stack can be triggered during provisioning
Published 2022-07-26 · Modified
8.8EPSS 0.008
CVE-2021-3321
Integer Underflow in Zephyr in IEEE 802154 Fragment Reassembly Header Removal
Published 2021-10-12 · Modified
8.8EPSS 0.008
CVE-2021-3835
Buffer overflow in usb device class
Published 2022-02-07 · Modified
8.8EPSS 0.007
CVE-2023-4259
Potential buffer overflow vulnerabilities in the Zephyr eS-WiFi driver
Published 2023-09-25 · Modified
8.8EPSS 0.007
CVE-2021-3330
RCE/DOS: Linked-list corruption leading to large out-of-bounds write while sorting for forged fragment list in Zephyr
Published 2021-10-12 · Modified
8.8EPSS 0.006
CVE-2020-10061
Error handling invalid packet sequence
Published 2020-06-05 · Modified
8.8EPSS 0.006
1 / 5Next →