Moos
Core-moos: vulnerabilidades y CVE
Core-moos tiene 12 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses12
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85455 | Alta (8.8) | 0.67% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the… |
| CVE-2026-85454 | Media (5.2) | 0.32% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line… |
| CVE-2026-85453 | Media (5.3) | 0.34% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads… |
| CVE-2026-85451 | Alta (7.1) | 0.36% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can… |
| CVE-2026-85450 | Alta (8.7) | 0.63% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless… |
| CVE-2026-85443 | Alta (8.7) | 0.63% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake. An… |
| CVE-2026-85442 | Alta (8.7) | 0.77% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers to trigger unbounded buffer allocation by sending crafted wire packets.… |
| CVE-2026-85441 | Alta (8.7) | 0.66% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted message with a negative length value to the MOOSDB… |
| CVE-2026-85440 | Crítica (9.3) | 1.0% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a negative packet length.… |
| CVE-2026-85432 | Alta (8.8) | 0.51% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized… |
| CVE-2026-85428 | Crítica (9.3) | 0.82% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable… |
| CVE-2026-85424 | Crítica (9.3) | 0.82% | — | 3 sept 2026 | MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time… |