Skip to main content

Vendor/product archive

openrobotics / robot_operating_system CVEs

Beta · best-effort

33 CVEs tagged to openrobotics / robot_operating_system17 Critical, 14 High, 1 Medium, 1 Low, 0 Unrated.

CVE-2025-3753

Published Jul 17, 2025

A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability ar…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41921

Published Jul 17, 2025

A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The v…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41148

Published Jul 17, 2025

A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The v…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39835

Published Jul 17, 2025

A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39289

Published Jul 17, 2025

A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39780

Published Apr 2, 2025

A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44856

Published Dec 6, 2024

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44855

Published Dec 6, 2024

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44852

Published Dec 6, 2024

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41650

Published Dec 6, 2024

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the n…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41649

Published Dec 6, 2024

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the e…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41648

Published Dec 6, 2024

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the n…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41647

Published Dec 6, 2024

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the n…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41646

Published Dec 6, 2024

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the n…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41645

Published Dec 6, 2024

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the n…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-41644

Published Dec 6, 2024

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ co…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-38927

Published Dec 6, 2024

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-38926

Published Dec 6, 2024

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-38925

Published Dec 6, 2024

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-38924

Published Dec 6, 2024

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-38923

Published Dec 6, 2024

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-38922

Published Dec 6, 2024

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sen…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-38921

Published Dec 6, 2024

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2