Openrobotics
Openrobotics Robot Operating System: vulnerabilidades y CVE
Openrobotics Robot Operating System tiene 32 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 17 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE32
Últimos 12 meses0
Críticas17
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-3753 | Alta (7.8) | 0.19% | — | 17 jul 2025 | A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() function… |
| CVE-2024-41921 | Alta (7.8) | 0.19% | — | 17 jul 2025 | A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability lies in the 'echo' verb,… |
| CVE-2024-41148 | Alta (7.8) | 0.19% | — | 17 jul 2025 | A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability lies in the 'hz' verb,… |
| CVE-2024-39835 | Alta (7.8) | 0.18% | — | 17 jul 2025 | A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the… |
| CVE-2024-39289 | Alta (7.8) | 0.18% | — | 17 jul 2025 | A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability stems from the use of the eval()… |
| CVE-2024-39780 | Crítica (9.8) | 0.39% | — | 2 abr 2025 | A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS… |
| CVE-2024-44856 | Alta (7.5) | 0.59% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner(). |
| CVE-2024-44855 | Alta (7.5) | 0.59% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner(). |
| CVE-2024-44854 | Alta (7.5) | 0.59% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan(). |
| CVE-2024-44853 | Alta (7.5) | 0.59% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl(). |
| CVE-2024-44852 | Crítica (9.8) | 0.60% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan(). |
| CVE-2024-41650 | Crítica (9.8) | 0.48% | — | 6 dic 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d. |
| CVE-2024-41649 | Crítica (9.8) | 0.70% | — | 6 dic 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_. |
| CVE-2024-41648 | Crítica (9.8) | 0.48% | — | 6 dic 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller. |
| CVE-2024-41647 | Crítica (9.8) | 0.70% | — | 6 dic 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller. |
| CVE-2024-41646 | Crítica (9.8) | 0.70% | — | 6 dic 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller. |
| CVE-2024-41645 | Crítica (9.8) | 0.70% | — | 6 dic 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl. |
| CVE-2024-41644 | Crítica (9.8) | 0.70% | — | 6 dic 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component. |
| CVE-2024-38927 | Crítica (9.8) | 0.59% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change… |
| CVE-2024-38926 | Crítica (9.8) | 0.59% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change… |
| CVE-2024-38925 | Crítica (9.8) | 0.59% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change… |
| CVE-2024-38924 | Crítica (9.8) | 0.55% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change… |
| CVE-2024-38923 | Crítica (9.8) | 0.55% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change… |
| CVE-2024-38922 | Crítica (9.8) | 0.59% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component… |
| CVE-2024-38921 | Crítica (9.8) | 0.60% | — | 6 dic 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change… |
| CVE-2024-30962 | Alta (7.8) | 0.29% | — | 5 dic 2024 | Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process |
| CVE-2024-30961 | Alta (7.8) | 0.29% | — | 5 dic 2024 | Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the error-thrown mechanism in… |
| CVE-2024-25199 | Alta (8.1) | 0.58% | — | 20 feb 2024 | Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free. |
| CVE-2024-25198 | Crítica (9.1) | 0.71% | — | 20 feb 2024 | Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free. |
| CVE-2024-25197 | Media (6.5) | 0.68% | — | 20 feb 2024 | Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp. |