MOOS 在 essential-moos 版本(从早期版本到 10.0.1)中存在一个缓冲区溢出漏洞。该漏洞位于 函数中,允许远程攻击者通过发送具有负数声明长度的 UDP 数据报来破坏堆内存。攻击者可以向配置的 UDP 监听端口发送精心构造的 UDP 数据包,从而触发一个过大的 操作,导致写入超出目标缓冲区边界,造成堆内存损坏和拒绝服务(DoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themoos | essential-moos | 0 ~ 10.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85440 | 9.8 CRITICAL | MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Negative Packet |
| CVE-2026-85433 | 9.8 CRITICAL | MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfiguration |
| CVE-2026-85424 | 9.8 CRITICAL | MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subscribe and DB_ |
| CVE-2026-85428 | 9.8 CRITICAL | MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write |
| CVE-2026-85430 | 9.1 CRITICAL | MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing |
| CVE-2026-85452 | 8.8 HIGH | MOOS ui-moos through 50b9c6c uMS Buffer Overflow via Long MOOS Identifiers |
| CVE-2026-85455 | 8.2 HIGH | MOOS core-moos through 10.4.0 MOOSDB Out-of-Bounds Read via Short Packet |
| CVE-2026-85432 | 8.2 HIGH | MOOS core-moos through 10.4.0 MOOSDB Message Source Spoofing via Wire Identity |
| CVE-2026-85427 | 8.1 HIGH | MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSI |
| CVE-2026-85441 | 7.5 HIGH | MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String Leng |
| CVE-2026-85443 | 7.5 HIGH | MOOS core-moos through 10.4.0 MOOSDB Accept Loop Denial of Service |
| CVE-2026-85431 | 7.5 HIGH | MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injection |
| CVE-2026-85450 | 7.5 HIGH | MOOS core-moos through 10.4.0 MOOSDB HTTP Server Resource Exhaustion |
| CVE-2026-85442 | 7.5 HIGH | MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet Allocation |
| CVE-2026-85451 | 7.1 HIGH | MOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multicast Passphra |
| CVE-2026-85454 | 6.1 MEDIUM | MOOS core-moos through 10.4.0 Off-by-One Buffer Overflow in Serial Telegram Handling |
| CVE-2026-85453 | 6.1 MEDIUM | MOOS core-moos through 10.4.0 MOOSDB HTTP Pages Stored Cross-Site Scripting |
No comments yet