Zephyr
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 23 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 18, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Stack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlers
Out-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify parsing
Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention
NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS)
Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body
Out-of-bounds read in coredump shell when printing stored-dump target code
Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace
Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via `uint16_t` length underflow
Kernel heap memory leak in `z_vrfy_k_poll()` lets an unprivileged user thread exhaust the kernel resource pool
Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)
Monitor Zephyr in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.