| BDSA-2025-4909 |
|
High |
Jun 06, 2025 |
We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very long DNS names. This issue only
more...
We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very long DNS names. This issue only affects systems using Buffer Allocation Scheme 1 with LLMNR or mDNS enabled.
Users should upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.
**Note: CVE details have been utilized in generating this advisory. The details of the vulnerability have not been independently verified by Black Duck CyRC.**
less...
|
|
| BDSA-2025-13812 |
|
Low |
Oct 13, 2025 |
FreeRTOS-Plus-TCP is vulnerable to NULL pointer dereference from missing validation in the IP version field during UDP/IPv6 packet processing. An attac
more...
FreeRTOS-Plus-TCP is vulnerable to NULL pointer dereference from missing validation in the IP version field during UDP/IPv6 packet processing. An attacker could exploit this by sending a crafted UDP/IPv6 packet with the incorrect version field which could cause invalid pointer dereference.
The vendor states the following:
>this issue only affects applications using ipv6.
less...
|
|
| BDSA-2025-13811 |
|
Medium |
Oct 13, 2025 |
FreeRTOS-Plus-TCP is vulnerable to buffer over-read due to missing validation of payload lengths in IPv6 packet headers, if IPV6 support has been enabl
more...
FreeRTOS-Plus-TCP is vulnerable to buffer over-read due to missing validation of payload lengths in IPv6 packet headers, if IPV6 support has been enabled. This could allow a remote attacker to perform out-of-bounds read operations when receiving IPv6 packets with incorrect payload lengths in the packet header, which could create a denial-of-service (DoS) condition or expose sensitive information.
less...
|
|
| BDSA-2025-13810 |
|
Medium |
Oct 13, 2025 |
FreeRTOS-Plus-TCP contains a buffer over-read vulnerability due to missing validation checks in the ICMPv6 packet processing code, if IPv6 support is e
more...
FreeRTOS-Plus-TCP contains a buffer over-read vulnerability due to missing validation checks in the ICMPv6 packet processing code, if IPv6 support is enabled. This could allow an attacker to perform out-of-bounds read operations when processing ICMPv6 packets that are smaller than the expected size, potentially resulting in a denial-of-service (DoS) condition or the exposure of sensitive information.
less...
|
|