Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.37% | — | Eclipse Threadx Netx DUO | 15/10/2025 | 17/6/2026 | In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was missing length verification of certain SSL/TLS client hello message: the ciphersuite length and compression method length. In case of an attacker-crafted message with values outside of the expected… | |
| Analizada | Alta (7.2) | 0.14% | — | Eclipse Threadx | 15/10/2025 | 17/6/2026 | In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write. | |
| Analizada | Media (5.7) | 0.17% | — | Eclipse Threadx | 15/10/2025 | 17/6/2026 | In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't performed, allowing, as a result, to obtain a thread with higher priority than expected and causing a possible denial of service. | |
| Analizada | Media (5.7) | 0.17% | — | Eclipse Threadx | 14/10/2025 | 17/6/2026 | In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region. Vulnerable system calls had a check of pointers, but that check wasn't verifying whether the pointer is outside the module memory region. | |
| Analizada | Alta (7.1) | 0.95% | — | Eclipse Threadx Netx DUO | 6/4/2025 | 17/6/2026 | In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resulting in the 404 error for each further file request. Users can work-around the… | |
| Analizada | Media (5.3) | 0.95% | — | Eclipse Threadx Netx DUO | 6/4/2025 | 17/6/2026 | In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length in one packet smaller than the data request size of the other packet. A… | |
| Analizada | Media (5.3) | 0.95% | — | Eclipse Threadx Netx DUO | 6/4/2025 | 17/6/2026 | In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length smaller than the data request size. A possible workaround is to… | |
| Analizada | Media (5.3) | 0.76% | — | Eclipse Threadx Netx DUO | 21/2/2025 | 17/6/2026 | In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length smaller than the data request size. A possible workaround is to disable HTTP… | |
| Analizada | Media (5.3) | 0.76% | — | Eclipse Threadx Netx DUO | 21/2/2025 | 17/6/2026 | In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length in one packet smaller than the data request size of the other packet. A… | |
| Analizada | Alta (7.1) | 0.76% | — | Eclipse Threadx Netx DUO | 21/2/2025 | 17/6/2026 | In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resulting in the 404 error for each further file request. Users can work-around the… | |
| Modificada | Crítica (9.8) | 0.91% | — | Eclipse Threadx Netx DUO | 26/3/2024 | 17/6/2026 | In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than expected. This could cause subsequent heap buffer overflows. | |
| Modificada | Alta (7.8) | 0.34% | — | Eclipse Threadx | 26/3/2024 | 17/6/2026 | In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. The affected file was ports/xtensa/xcc/src/tx_clib_lock.c | |
| Modificada | Alta (7.8) | 0.55% | — | Eclipse Threadx | 26/3/2024 | 17/6/2026 | In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. This could lead to integer wraparound, under-allocations and heap buffer overflows. | |
| Modificada | Crítica (9.8) | 0.93% | — | Eclipse Threadx Usbx | 5/12/2023 | 17/6/2026 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference vulnerabilities in Azure RTOS USBX. The affected components include functions/processes in host stack and host… | |
| Modificada | Crítica (9.8) | 1.2% | — | Eclipse Threadx Usbx | 5/12/2023 | 17/6/2026 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to memory buffer and pointer vulnerabilities in Azure RTOS USBX. The affected components include functions/processes in pictbridge and host class,… | |
| Modificada | Crítica (9.8) | 0.95% | — | Eclipse Threadx Usbx | 5/12/2023 | 17/6/2026 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference vulnerabilities in Azure RTOS USBX. The affected components include components in host class, related to CDC ACM in… | |
| Modificada | Crítica (9.8) | 1.2% | — | Eclipse Threadx Usbx | 5/12/2023 | 17/6/2026 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to out of bounds write vulnerabilities in Azure RTOS USBX. The affected components include functions/processes in host and device classes, related… | |
| Modificada | Crítica (9.8) | 1.3% | — | Eclipse Threadx Usbx | 5/12/2023 | 17/6/2026 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference and type confusion vulnerabilities in Azure RTOS USBX. The affected components include functions/processes in host… | |
| Modificada | Crítica (9.8) | 1.3% | — | Microsoft Azure Rtos Threadx | 5/12/2023 | 17/6/2026 | Azure RTOS ThreadX is an advanced real-time operating system (RTOS) designed specifically for deeply embedded applications. An attacker can cause arbitrary read and write due to vulnerability in parameter checking mechanism in Azure RTOS ThreadX, which may lead to privilege escalation. The affected components include… | |
| Modificada | Crítica (9.8) | 0.72% | — | Eclipse Threadx Usbx | 13/10/2022 | 17/6/2026 | Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. The case is, in [_ux_host_class_pima_read](https://github.com/azure-rtos/usbx/blob/master/common/usbx_host_classes/src/ux_host_class_pima_read.c), there is data length from… | |
| Modificada | Crítica (9.8) | 1.7% | — | Eclipse Threadx Usbx | 10/10/2022 | 17/6/2026 | Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and available for all Azure RTOS ThreadX–supported processors. Azure RTOS USBX implementation of host support for USB CDC ECM includes an integer underflow and a buffer overflow in the… | |
| Modificada | Crítica (9.8) | 2.3% | — | Eclipse Threadx Usbx | 24/5/2022 | 17/6/2026 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. Prior to version 6.1.11, he USBX DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In particular cases this may allow an attacker to bypass security features or execute arbitrary… | |
| Modificada | Crítica (9.8) | 1.2% | — | Eclipse Threadx Usbx | 24/5/2022 | 17/6/2026 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can cause a buffer overflow by providing the Azure RTOS USBX host stack a HUB descriptor with `bNbPorts` set to a value greater than `UX_MAX_TT` which defaults to 8. For a `bNbPorts` value of 255, the… |