Protobuf-C Project Protobuf-C vulnerabilities
2 known vulnerabilities affecting protobuf-c_project/protobuf-c.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2022-48468MEDIUMCVSS 5.5fixed in 1.4.12023-04-13
CVE-2022-48468 [MEDIUM] CWE-190 CVE-2022-48468: protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.
protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.
nvdosv
CVE-2022-33070MEDIUMCVSS 5.5v1.4.02022-06-23
CVE-2022-33070 [MEDIUM] CVE-2022-33070: Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_a
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
nvdosv