zephyrproject
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 164 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 6, 2018 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver
Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`
SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads
Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count)
Heap buffer overflow on WireGuard receive path via unbounded incoming packet length
Use-after-free / double-free of the root USB device in the experimental USB host stack
NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume
Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
NULL-pointer dereference DoS in MAX32 USB device controller transfer-completion handlers
Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it
Monitor zephyrproject in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.