Skip to main content

Vendor/product archive

apache / nuttx CVEs

Beta · best-effort

9 CVEs tagged to apache / nuttx7 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2025-48769

Published Jan 1, 2026

Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer var…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48768

Published Jan 1, 2026

Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47869

Published Jun 16, 2025

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability was discovered in Apache NuttX RTOS apps/exapmles/xmlrpc application. In this example applica…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-47868

Published Jun 16, 2025

Out-of-bounds Write resulting in possible Heap-based Buffer Overflow vulnerability was discovered in tools/bdf-converter font conversion utility that is part of Apache NuttX RTOS…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-35003

Published May 26, 2025

Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities were discovered in Apache NuttX RTOS Bluetooth Stack (HCI a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-26461

Published Jun 21, 2021

Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-17529

Published Dec 9, 2020

Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invali…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-17528

Published Dec 9, 2020

Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-1939

Published May 12, 2020

The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs. One of these, ftpd, had a NU…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1