| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-0553 | Possible to retrieve uncrypted firmware image | zephyrproject-rtos | zephyr | Medium | 6.5 | 2023-01-11 00:00:00 | Deep Dive |
| CVE-2022-2993 | bt: host: Wrong key validation check | zephyrproject-rtos | zephyr | High | 8.6 | 2022-12-12 01:50:00 | Deep Dive |
| CVE-2022-2741 | can: denial-of-service can be triggered by a crafted CAN frame | zephyrproject-rtos | zephyr | High | 8.2 | 2022-10-31 17:45:10 | Deep Dive |
| CVE-2022-2839 | Zephyr Project Manager < 3.2.55 - Unauthorised AJAX Calls To Stored XSS | Unknown | Zephyr Project Manager | 中危 | - | 2022-10-03 13:45:24 | Deep Dive |
| CVE-2022-3333 | Zephyr Project Manager REST Call cross site scripting | Zephyr | Project Manager | Low | 3.5 | 2022-09-28 04:35:12 | Deep Dive |
| CVE-2022-2840 | Zephyr Project Manager < 3.2.5 - Multiple Unauthenticated SQLi | Unknown | Zephyr Project Manager | 超危 | - | 2022-09-19 00:00:00 | Deep Dive |
| CVE-2022-1841 | Out-of-bound write in tcp_flags | zephyrproject-rtos | zephyr | High | 7.2 | 2022-08-31 19:40:09 | Deep Dive |
| CVE-2022-1042 | Out-of-bound write vulnerability in the Bluetooth mesh core stack can be triggered during provisioning | zephyrproject-rtos | zephyr | High | 8.2 | 2022-07-26 04:25:22 | Deep Dive |
| CVE-2022-1041 | Out-of-bound write vulnerability in the Bluetooth mesh core stack can be triggered during provisioning | zephyrproject-rtos | zephyr | High | 8.2 | 2022-07-26 04:25:10 | Deep Dive |
| CVE-2021-3435 | L2CAP: Information leakage in le_ecred_conn_req() | zephyrproject-rtos | zephyr | Medium | 4.0 | 2022-06-28 19:45:45 | Deep Dive |
| CVE-2021-3434 | L2CAP: Stack based buffer overflow in le_ecred_conn_req() | zephyrproject-rtos | zephyr | Medium | 4.9 | 2022-06-28 19:45:40 | Deep Dive |
| CVE-2021-3433 | BT: Invalid channel map in CONNECT_IND results to Deadlock | zephyrproject-rtos | zephyr | Medium | 4.0 | 2022-06-28 19:45:34 | Deep Dive |
| CVE-2021-3432 | BT: Invalid interval in CONNECT_IND leads to Division by Zero | zephyrproject-rtos | zephyr | Medium | 4.3 | 2022-06-28 19:45:29 | Deep Dive |
| CVE-2021-3431 | BT: Assertion failure on repeated LL_FEATURE_REQ | zephyrproject-rtos | zephyr | Medium | 4.3 | 2022-06-28 19:45:24 | Deep Dive |
| CVE-2021-3430 | BT: Assertion failure on repeated LL_CONNECTION_PARAM_REQ | zephyrproject-rtos | zephyr | Medium | 6.5 | 2022-06-28 19:45:20 | Deep Dive |
| CVE-2022-1822 | Zephyr Project Manager <= 3.2.40 - Reflected Cross-Site Scripting | dylanjkotze | Zephyr Project Manager | Medium | 6.1 | 2022-06-13 12:25:29 | Deep Dive |
| CVE-2021-3861 | The RNDIS USB device class includes a buffer overflow vulnerability | zephyrproject-rtos | zephyr | High | 8.2 | 2022-02-07 22:00:14 | Deep Dive |
| CVE-2021-3835 | Buffer overflow in usb device class | zephyrproject-rtos | zephyr | High | 8.2 | 2022-02-07 22:00:12 | Deep Dive |
| CVE-2021-3454 | Truncated L2CAP K-frame causes assertion failure | zephyrproject-rtos | zephyr | Medium | 4.3 | 2021-10-19 22:50:09 | Deep Dive |
| CVE-2021-3455 | Disconnecting L2CAP channel right after invalid ATT request leads freeze | zephyrproject-rtos | zephyr | Medium | 4.3 | 2021-10-19 22:25:09 | Deep Dive |