Windriver / Vxworks
38 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-51787 | An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task memory is not free… | HIGH | 7.5 | Feb 15, 2024 |
| CVE-2023-38346 | An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an… | HIGH | 8.8 | Sep 22, 2023 |
| CVE-2022-38767 | An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during… | HIGH | 7.5 | Nov 25, 2022 |
| CVE-2022-23937 | In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario. | HIGH | 7.5 | Mar 29, 2022 |
| CVE-2021-43268 | An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a doub… | MEDIUM | 6.5 | Nov 24, 2021 |
| CVE-2020-35198 | An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by c… | CRITICAL | 9.8 | May 12, 2021 |
| CVE-2021-29997 | An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE. | MEDIUM | 5.3 | Apr 13, 2021 |
| CVE-2021-29999 | An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server. | CRITICAL | 9.8 | Apr 13, 2021 |
| CVE-2021-29998 | An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client. | CRITICAL | 9.8 | Apr 13, 2021 |
| CVE-2016-20009 | A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that… | CRITICAL | 9.8 | Mar 11, 2021 |
| CVE-2020-28895 | integer overflow in calloc | HIGH | 7.3 | Feb 3, 2021 |
| CVE-2020-11440 | httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root. | HIGH | 7.5 | Jul 23, 2020 |
| CVE-2020-10664 | The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference. | HIGH | 7.5 | Apr 27, 2020 |
| CVE-2019-12262 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Re… | CRITICAL | 9.8 | Aug 14, 2019 |
| CVE-2019-12261 | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointe… | CRITICAL | 9.8 | Aug 9, 2019 |
| CVE-2019-12260 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state con… | CRITICAL | 9.8 | Aug 9, 2019 |
| CVE-2019-12258 | Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP o… | HIGH | 7.5 | Aug 9, 2019 |
| CVE-2019-12255 | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an i… | CRITICAL | 9.8 | Aug 9, 2019 |
| CVE-2019-12265 | Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Informa… | MEDIUM | 5.3 | Aug 9, 2019 |
| CVE-2019-12263 | Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state… | HIGH | 8.1 | Aug 9, 2019 |
| CVE-2019-12259 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL d… | HIGH | 7.5 | Aug 9, 2019 |
| CVE-2019-12256 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 pac… | CRITICAL | 9.8 | Aug 9, 2019 |
| CVE-2019-12257 | Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/AC… | HIGH | 8.8 | Aug 9, 2019 |
| CVE-2019-12264 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component. | HIGH | 7.1 | Aug 5, 2019 |
| CVE-2019-9865 | When RPC is enabled in Wind River VxWorks 6.9 prior to 6.9.1, a specially crafted RPC request can trigger an integer overflow leading to an out-of-bounds memor… | HIGH | 8.1 | May 29, 2019 |
Showing 1 to 25 of 38 CVEs