Skip to main content

Vendor/product archive

windriver / vxworks CVEs

Beta · best-effort

39 CVEs tagged to windriver / vxworks13 Critical, 17 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2023-51787

Published Feb 15, 2024

An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task memory is not freed, resulting in a me…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38346

Published Sep 22, 2023

An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have re…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38767

Published Nov 25, 2022

An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23937

Published Mar 29, 2022

In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43268

Published Nov 24, 2021

An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a double free.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29999

Published Apr 13, 2021

An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-29997

Published Apr 13, 2021

An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-20009

Published Mar 11, 2021

A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer suppor…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2020-11440

Published Jul 23, 2020

httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10664

Published Apr 27, 2020

The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2