Ericsson
Ericsson Codechecker: vulnerabilidades y CVE
Ericsson Codechecker tiene 10 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses4
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-58107 | Media (5.5) | 0.41% | — | 28 ago 2026 | CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store… |
| CVE-2026-58106 | Baja (2) | 0.17% | — | 28 ago 2026 | CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r was fixed by replacing unchecked strcpy() with a bounded safe_strcpy() helper. At ldlogger-tool-gcc.c:129 the destination passed to that helper is… |
| CVE-2026-25660 | Crítica (9.3) | 0.61% | — | 24 abr 2026 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls. This… |
| CVE-2025-40843 | Alta (7.8) | 0.19% | — | 28 oct 2025 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. CodeChecker versions up to 6.26.1 contain a buffer overflow vulnerability in the internal ldlogger… |
| CVE-2025-1300 | Media (6.1) | 0.27% | — | 28 feb 2025 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server contains an open redirect vulnerability due to missing protections… |
| CVE-2024-53829 | Alta (8.2) | 0.25% | — | 21 ene 2025 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Cross-site request forgery allows an unauthenticated attacker to hijack the authentication of a… |
| CVE-2024-10082 | Crítica (9) | 0.48% | — | 6 nov 2024 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external… |
| CVE-2024-10081 | Crítica (10) | 40% | — | 6 nov 2024 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL ends with Authentication. This bypass allows superuser… |
| CVE-2023-49793 | Media (6.5) | 0.73% | — | 24 jun 2024 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the server endpoint of `CodeChecker store` are not properly sanitized. An… |
| CVE-2021-44217 | Media (6.1) | 1.6% | — | 18 ene 2022 | In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Ericsson
Packet Core Controller · 9Network Manager · 8Indoor Connect 8855 Firmware · 8Packet Core Gateway · 3Drutt Mobile Service Delivery Platform · 3Bscs IX R18 Billing & Rating Admx · 2Enterprise Content Management · 2Operations Support System-radio AND Core Firmware · 2Bscs IX R18 Billing & Rating MX · 2RAN Compute AND Site Controller 6610 · 2Hm220dp Adsl Modem · 1Active Library Explorer · 1