MOOS 核心组件(core-moos)在 10.4.0 及更早版本中存在拒绝服务(DoS)漏洞,位于 函数中。具体而言,接受连接线程在进行线缆协议(wire-protocol)握手时,执行了一个无超时的阻塞式接收操作。 攻击者只需向 MOOSDB 端口建立 TCP 连接但不发送任何数据,即可导致接受线程无限期阻塞。由于该线程在阻塞期间仍持有 socket 列表锁(socket-list lock),这将阻止所有后续客户端连接,从而引发服务不可用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85440 | 9.8 CRITICAL | MOOS core-moos through 10.4.0 MOOSDB Pre-Authentication Heap Overflow via Negative Packet |
| CVE-2026-85433 | 9.8 CRITICAL | MOOS essential-moos through 10.0.1 pShare Unauthorized Runtime Route Reconfiguration |
| CVE-2026-85424 | 9.8 CRITICAL | MOOS core-moos through 10.4.0 Missing Authentication for MOOSDB Publish, Subscribe and DB_ |
| CVE-2026-85428 | 9.8 CRITICAL | MOOS core-moos through 10.4.0 MOOSDB HTTP Server Unauthenticated Variable Write |
| CVE-2026-85430 | 9.1 CRITICAL | MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing |
| CVE-2026-85452 | 8.8 HIGH | MOOS ui-moos through 50b9c6c uMS Buffer Overflow via Long MOOS Identifiers |
| CVE-2026-85455 | 8.2 HIGH | MOOS core-moos through 10.4.0 MOOSDB Out-of-Bounds Read via Short Packet |
| CVE-2026-85432 | 8.2 HIGH | MOOS core-moos through 10.4.0 MOOSDB Message Source Spoofing via Wire Identity |
| CVE-2026-85427 | 8.1 HIGH | MOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSI |
| CVE-2026-85436 | 7.5 HIGH | MOOS essential-moos through 10.0.1 pMOOSBridge Heap Corruption via Negative UDP Length |
| CVE-2026-85450 | 7.5 HIGH | MOOS core-moos through 10.4.0 MOOSDB HTTP Server Resource Exhaustion |
| CVE-2026-85441 | 7.5 HIGH | MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String Leng |
| CVE-2026-85431 | 7.5 HIGH | MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injection |
| CVE-2026-85442 | 7.5 HIGH | MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Unbounded Packet Allocation |
| CVE-2026-85451 | 7.1 HIGH | MOOS core-moos through 10.4.0 Remote Process Termination via Hard-Coded Multicast Passphra |
| CVE-2026-85454 | 6.1 MEDIUM | MOOS core-moos through 10.4.0 Off-by-One Buffer Overflow in Serial Telegram Handling |
| CVE-2026-85453 | 6.1 MEDIUM | MOOS core-moos through 10.4.0 MOOSDB HTTP Pages Stored Cross-Site Scripting |
No comments yet