Nanopb Project
Nanopb Project Nanopb: vulnerabilidades y CVE
Nanopb Project Nanopb tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE4
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2014-125106 | Crítica (9.8) | 0.95% | — | 17 jun 2023 | Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string. |
| CVE-2021-21401 | Alta (7.1) | 1.8% | — | 23 mar 2021 | Nanopb is a small code-size Protocol Buffers implementation in ansi C. In Nanopb before versions 0.3.9.8 and 0.4.5, decoding a specifically formed message can cause invalid `free()` or `realloc()` calls if the message… |
| CVE-2020-26243 | Alta (7.5) | 2.7% | — | 25 nov 2020 | Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can leak memory if dynamic allocation is enabled and an oneof field contains… |
| CVE-2020-5235 | Crítica (9.8) | 1.7% | — | 4 feb 2020 | There is a potentially exploitable out of memory condition In Nanopb before 0.4.1, 0.3.9.5, and 0.2.9.4. When nanopb is compiled with PB_ENABLE_MALLOC, the message to be decoded contains a repeated string, bytes or… |