Apache Software Foundation Apache Nuttx vulnerabilities

3 known vulnerabilities affecting apache_software_foundation/apache_nuttx.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3

Vulnerabilities

Page 1 of 1
CVE-2021-26461CRITICALCVSS 9.8≥ Apache NuttX, < 10.1.02021-06-21
CVE-2021-26461 [CRITICAL] CWE-190 CVE-2021-26461: Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, rea Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
cvelistv5nvd
CVE-2020-17528CRITICALCVSS 9.1≥ unspecified, < 9.1.1v10.0.02020-12-09
CVE-2020-17528 [CRITICAL] CWE-787 CVE-2020-17528: Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and inclu Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the packet.
cvelistv5nvd
CVE-2020-17529CRITICALCVSS 9.8≥ unspecified, ≤ 9.1.0v10.0.02020-12-09
CVE-2020-17529 [CRITICAL] CWE-787 CVE-2020-17529: Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and inclu Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offset value specified in the IP header. This is only impacts builds with both CONFIG_EXPERIMENTAL and CONFIG_NET_TCP_REASSEMBLY build flags enabled.
cvelistv5nvd