Zephyr
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 27 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 18, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Out-of-bounds write in the IEEE 802.15.4 L2 transmit path for oversized non-6LoWPAN frames
Use-after-free / double-free from unsynchronized concurrent access to the TLS client session cache in Zephyr sockets
NULL pointer dereference in Zephyr MQTT-SN client when removing a non-responsive gateway
Out-of-bounds stack write in the settings NVS backend from over-reported nvs_read length
Stack buffer overflow and off-by-one writes in Zephyr HL7800 modem AT response handlers
Out-of-bounds stack read and write in Zephyr WNC-M14A2A modem socket-notify parsing
Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention
NULL-pointer dereference in UpdateHub OTA agent on empty inner metadata array (remote DoS)
Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body
Out-of-bounds read in coredump shell when printing stored-dump target code
Monitor Zephyr in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.