cbcvebase.

Silicon Labs Gecko Platform vulnerabilities

9 known vulnerabilities affecting silicon_labs/gecko_platform.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-45318P2CRITICALCVSS 9.8vSilicon Labs Gecko Platform 4.3.2.02024-02-20
CVE-2023-45318 [CRITICAL] CWE-122 CVE-2023-45318: A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedde A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
nvd
CVE-2023-27882P3CRITICALCVSS 9.8v4.3.1.02023-11-14
CVE-2023-27882 [CRITICAL] CWE-122 CVE-2023-27882: A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
nvd
CVE-2023-25181P3CRITICALCVSS 9.8v4.3.1.02023-11-14
CVE-2023-25181 [CRITICAL] CWE-122 CVE-2023-25181: A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedde A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
nvd
CVE-2023-28379P3CRITICALCVSS 9.8v4.3.1.02023-11-14
CVE-2023-28379 [CRITICAL] CWE-119 CVE-2023-28379: A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Em A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
nvd
CVE-2023-24585P3CRITICALCVSS 9.8v4.3.1.02023-11-14
CVE-2023-24585 [CRITICAL] CWE-119 CVE-2023-24585: An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-H An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
nvd
CVE-2023-31247P3CRITICALCVSS 9.8v4.3.1.02023-11-14
CVE-2023-31247 [CRITICAL] CWE-119 CVE-2023-31247: A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Wes A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
nvd
CVE-2023-28391P3CRITICALCVSS 9.8v4.3.1.02023-11-14
CVE-2023-28391 [CRITICAL] CWE-119 CVE-2023-28391: A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston E A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
nvd
CVE-2023-39540P4MEDIUMCVSS 5.9v4.3.1.02024-02-20
CVE-2023-39540 [MEDIUM] CWE-126 CVE-2023-39540: A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embe A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within the parsing an IPv4 ICMP packet
nvd
CVE-2023-39541P4MEDIUMCVSS 5.9v4.3.1.02024-02-20
CVE-2023-39541 [MEDIUM] CWE-126 CVE-2023-39541: A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embe A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead to an out-of-bounds read. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability concerns a denial of service within the parsing an IPv6 ICMPv6 pack
nvd
Silicon Labs Gecko Platform vulnerabilities | cvebase