Ericsson / CodeChecker
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-58107 | Authenticated Remote Denial of Service via Unbounded zlib Decompression in massStoreRun | MEDIUM | 5.5 | Aug 28, 2026 |
| CVE-2026-58106 | Incomplete fix for CVE-2025-40843: safe_strcpy is called with PATH_MAX into fullPath+2, writing 2 bytes past the buffer on every CodeChecker log invocation | LOW | 2.0 | Aug 28, 2026 |
| CVE-2026-58108 | Personal access token delete filters on Session columns while deleting from PersonalAccessTokenDB | LOW | 1.2 | Aug 26, 2026 |
| CVE-2026-25660 | Authentication bypass for certain API calls | CRITICAL | 9.3 | Apr 24, 2026 |
| CVE-2025-40843 | Buffer overflow in CodeChecker log command | HIGH | 7.8 | Oct 28, 2025 |
| CVE-2025-1300 | Open redirect in CodeChecker web server | MEDIUM | 6.1 | Feb 28, 2025 |
| CVE-2024-53829 | Cross-Site Request Forgery in CodeChecker API | HIGH | 8.2 | Jan 21, 2025 |
| CVE-2024-10082 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows l… | CRITICAL | 9.4 | Nov 6, 2024 |
| CVE-2024-10081 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the AP… | CRITICAL | 9.9 | Nov 6, 2024 |
| CVE-2023-49793 | Path traversal in `CodeChecker server` in the endpoint of `CodeChecker store` | MEDIUM | 6.5 | Jun 24, 2024 |
| CVE-2021-44217 | In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attacke… | MEDIUM | 6.1 | Jan 18, 2022 |
Showing 1 to 9 of 9 CVEs