Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 0.35% | — | Contiki-ng | 26/1/2023 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to and including 4.8 are vulnerable to an out-of-bounds write that can occur in the BLE-L2CAP module. The Bluetooth Low Energy - Logical Link Control and Adaptation Layer Protocol (BLE-L2CAP) module handles… | |
| Modificada | Media (6.5) | 0.21% | — | Contiki-ng | 16/12/2022 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 contain a NULL Pointer Dereference in BLE L2CAP module. The Contiki-NG operating system for IoT devices contains a Bluetooth Low Energy stack. An attacker can inject a packet in this stack, which causes… | |
| Modificada | Media (5.4) | 0.26% | — | Contiki-ng | 11/11/2022 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 are vulnerable to an Out-of-bounds read. While processing the L2CAP protocol, the Bluetooth Low Energy stack of Contiki-NG needs to map an incoming channel ID to its metadata structure. While looking up… | |
| Modificada | Alta (8.8) | 0.76% | — | Contiki-ng | 1/9/2022 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementation in the Contiki-NG operating system (file os/net/ipv6/sicslowpan.c) contains an input function that processes incoming packets and copies them into a packet buffer. Because of a missing length check… | |
| Modificada | Alta (8.8) | 0.61% | — | Contiki-ng | 1/9/2022 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The low-power IPv6 network stack of Contiki-NG has a buffer module (os/net/ipv6/uipbuf.c) that processes IPv6 extension headers in incoming data packets. As part of this processing, the function uipbuf_get_next_header casts… | |
| Modificada | Alta (8.8) | 0.64% | — | Contiki-ng | 1/9/2022 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementation in Contiki-NG may cast a UDP header structure at a certain offset in a packet buffer. The code does not check whether the packet buffer is large enough to fit a full UDP header structure from the… | |
| Modificada | Crítica (9.8) | 2.1% | — | Contiki-ng | 4/8/2022 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol implementation in the Contiki-NG operating system, an incoming DODAG Information Option (DIO) control message can contain a prefix information option with a length parameter. The value of the length… | |
| Modificada | Alta (7.5) | 1.2% | — | Contiki-ng | 4/8/2022 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. Because of insufficient validation of IPv6 neighbor discovery options in Contiki-NG, attackers can send neighbor solicitation packets that trigger an out-of-bounds read. The problem exists in the module os/net/ipv6/uip-nd6.c, where memory… | |
| Modificada | Alta (8.1) | 1.3% | — | Contiki-ng | 4/8/2022 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. In affected versions it is possible to cause a buffer overflow when copying an IPv6 address prefix in the RPL-Classic implementation in Contiki-NG. In order to trigger the vulnerability, the Contiki-NG system must have joined an RPL DODAG.… | |
| Modificada | Alta (8.8) | 0.95% | — | Contiki-ng | 7/12/2021 | 17/6/2026 | A buffer overflow in os/net/mac/ble/ble-l2cap.c in the BLE stack in Contiki-NG 4.4 and earlier allows an attacker to execute arbitrary code via malicious L2CAP frames. | |
| Modificada | Crítica (9.1) | 1.6% | — | Contiki-ng | 19/10/2021 | 17/6/2026 | An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service and potentially disclose information via crafted SNMP packets to snmp_ber_decode_string_len_buffer in os/net/app-layer/snmp/snmp-ber.c. | |
| Modificada | Alta (7.5) | 0.96% | — | Contiki-os Contiki | 5/9/2021 | 17/6/2026 | In Contiki 3.0, Telnet option negotiation is mishandled. During negotiation between a server and a client, the server may fail to give the WILL/WONT or DO/DONT response for DO and WILL commands because of improper handling of exception condition, which leads to property violations and denial of service. Specifically,… | |
| Modificada | Alta (7.5) | 0.96% | — | Contiki-os Contiki | 10/8/2021 | 17/6/2026 | In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients entering an infinite loop and waiting forever, which may cause excessive CPU consumption. | |
| Modificada | Alta (7.5) | 1.3% | — | Contiki-os Contiki | 10/8/2021 | 17/6/2026 | In Contiki 3.0, a buffer overflow in the Telnet service allows remote attackers to cause a denial of service because the ls command is mishandled when a directory has many files with long names. | |
| Modificada | Alta (7.5) | 0.94% | — | Contiki-os Contiki | 9/8/2021 | 17/6/2026 | In Contiki 3.0, potential nonterminating acknowledgment loops exist in the Telnet service. When the negotiated options are already disabled, servers still respond to DONT and WONT requests with WONT or DONT commands, which may lead to infinite acknowledgment loops, denial of service, and excessive CPU consumption. | |
| Modificada | Crítica (9.1) | 1.2% | — | Contiki-ng | 18/6/2021 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be triggered by 6LoWPAN packets sent to devices running Contiki-NG 4.6 and prior. The IPv6 header decompression function (<code>uncompress_hdr_iphc</code>) does not perform proper boundary checks… | |
| Modificada | Crítica (9.8) | 0.92% | — | Contiki-ng | 18/6/2021 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After establishing a TCP socket using the tcp-socket library, it is possible for the remote end to send a packet with a data offset that is… | |
| Modificada | Crítica (9.8) | 1.1% | — | Contiki-ng | 18/6/2021 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an out-of-bounds write in versions of Contiki-NG prior to 4.6 when transmitting a 6LoWPAN packet with a chain of extension headers. Unfortunately, the written header is not checked to be within the… | |
| Modificada | Alta (7.5) | 0.98% | — | Contiki-ng | 18/6/2021 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In verions prior to 4.6, an attacker can perform a denial-of-service attack by triggering an infinite loop in the processing of IPv6 neighbor solicitation (NS) messages. This type of attack can effectively shut down the… | |
| Modificada | Alta (7.5) | 1.1% | — | Contiki-ng | 18/6/2021 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for internet of things devices. The RPL-Classic and RPL-Lite implementations in the Contiki-NG operating system versions prior to 4.6 do not validate the address pointer in the RPL source routing header This makes it possible for an attacker to cause… | |
| Modificada | Crítica (9.8) | 0.99% | — | Contiki-ng | 18/6/2021 | 17/6/2026 | Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In versions prior to 4.5, buffer overflow can be triggered by an input packet when using either of Contiki-NG's two RPL implementations in source-routing mode. The problem has been patched in Contiki-NG 4.5. Users can apply… | |
| Modificada | Alta (7.5) | 1.3% | — | Contiki-os Contiki | 24/3/2021 | 17/6/2026 | An issue was discovered in Contiki through 3.0. When sending an ICMPv6 error message because of invalid extension header options in an incoming IPv6 packet, there is an attempt to remove the RPL extension headers. Because the packet length and the extension header length are unchecked (with respect to the available… | |
| Modificada | Crítica (9.8) | 28% | — | Contiki-os | 11/12/2020 | 17/6/2026 | An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extension lengths. This leads to Denial-of-Service and potential Remote Code Execution via a crafted ICMPv6 echo packet. | |
| Modificada | Crítica (9.8) | 21% | — | Contiki-os | 11/12/2020 | 17/6/2026 | An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header length. This leads to Denial-of-Service and potential Remote Code Execution via a crafted ICMPv6 echo packet. | |
| Modificada | Crítica (9.8) | 59% | — | Contiki-ngContiki-os Contiki | 11/12/2020 | 17/6/2026 | An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't verify whether the address in the answer's length is sane. Therefore, when copying an address of an arbitrary length, a buffer overflow can occur. This bug can be exploited… |