Product
contiki ng contiki ng
55 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-47181
CVE-2024-41126
CVE-2024-41125
CVE-2023-29001
CVE-2023-50927
CVE-2023-50926
CVE-2023-48229
CVE-2021-42147
CVE-2021-42146
CVE-2021-42145
CVE-2021-42144
CVE-2021-42143
CVE-2021-42142
CVE-2021-42141
CVE-2020-27634
CVE-2023-37459
CVE-2023-37281
CVE-2023-34101
CVE-2023-34100
CVE-2023-31129
CVE-2023-30546
CVE-2023-28116
CVE-2023-23609
CVE-2022-41972
CVE-2022-41873
CVE-2022-36054
CVE-2022-36053
CVE-2022-36052
CVE-2022-35927
CVE-2022-35926
CVE-2021-32771
CVE-2020-12140
CVE-2020-12141
CVE-2021-21410
CVE-2021-21281
CVE-2021-21280
CVE-2021-21279
CVE-2021-21257
CVE-2021-21282
CVE-2020-24336
CVE-2020-13988
CVE-2020-14936
CVE-2020-14935
CVE-2020-14934
CVE-2020-14937
CVE-2019-9183
CVE-2019-8359
CVE-2018-20579
CVE-2018-19417
CVE-2018-1000804
CVE-2018-16667
CVE-2018-16666
CVE-2018-16665
CVE-2018-16664
CVE-2018-16663
<= 4.9
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An unaligned memory access can be triggered in the
<= 4.9
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered wh
<= 4.9
Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered wh
<= 4.9
Contiki-NG is an open-source, cross-platform operating system for IoT devices. The Contiki-NG operating system processes source ro
< 4.9
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An attacker can trigger out-of-boun
<= 4.9
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be caused
<= 4.9
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds write exists in th
all versions
Buffer over-read vulnerability in the dtls_sha256_update function in Contiki-NG tinyDTLS through master branch 53a0d97 allows remo
all versions
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the sam
<= 2018-08-30
An assertion failure discovered in check_certificate_request() in Contiki-NG tinyDTLS through master branch 53a0d97 allows atta
<= 2018-08-30
Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive information
<= 2018-08-30
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the handling of a
<= 2018-08-30
An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a large epoc
<= 2018-08-30
An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with different epoch num
all versions
In Contiki 4.5, TCP ISNs are improperly random.
<= 4.9
Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when a packet is received, the Contik
<= 4.9
Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when processing the various IPv6 head
<= 4.8
Contiki-NG is an operating system for internet of things devices. In version 4.8 and prior, when processing ICMP DAO packets in th
<= 4.8
Contiki-NG is an open-source, cross-platform operating system for IoT devices. When reading the TCP MSS option value from an incom
<= 4.8
The Contiki-NG operating system versions 4.8 and prior can be triggered to dereference a NULL pointer in the message handling code
<= 4.8
Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope database ma
<= 4.8
Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an
<= 4.8
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to and including 4.8
<= 4.8
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 contain a NUL
< 4.9
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 are vulnerabl
< 4.8
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementation in the C
< 4.8
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The low-power IPv6 network stack of
< 4.8
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementation in Conti
< 4.7
Contiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol implementation
< 4.8
Contiki-NG is an open-source, cross-platform operating system for IoT devices. Because of insufficient validation of IPv6 neighbor
< 4.8
Contiki-NG is an open-source, cross-platform operating system for IoT devices. In affected versions it is possible to cause a buff
<= 4.4
A buffer overflow in os/net/mac/ble/ble-l2cap.c in the BLE stack in Contiki-NG 4.4 and earlier allows an attacker to execute arbit
<= 4.4
An out-of-bounds read in the SNMP stack in Contiki-NG 4.4 and earlier allows an attacker to cause a denial of service and potentia
<= 4.6
Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be trigge
< 4.6
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exis
< 4.6
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an out-of-bo
< 4.6
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In verions prior to 4.6, an attacker
< 4.6
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. The RPL-Classic and RPL-Lite impleme
< 4.5
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. In versions prior to 4.5, buffer ove
<= 4.5
An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64
<= 3.0
An issue was discovered in Contiki through 3.0. An Integer Overflow exists in the uIP TCP/IP Stack component when parsing TCP MSS
>= 4.4 and <= 4.5
Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. Functions parsing the OIDs in SNMP requests lac
>= 4.0 and <= 4.5
Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP bulk get request response encoding function. The funct
>= 4.4 and <= 4.5
Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. The function parsing the received SNMP request
>= 4.4 and <= 4.5
Memory access out of buffer boundaries issues was discovered in Contiki-NG 4.4 through 4.5, in the SNMP BER encoder/decoder. The l
<= 4.3
An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. A buffer overflow is present due to an integer underflo
<= 4.3
An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. An out of bounds write is present in the data section d
all versions
Contiki-NG before 4.2 has a stack-based buffer overflow in the push function in os/lib/json/jsonparse.c that allows an out-of-boun
< 4.2
An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH me
all versions
contiki-ng version 4 contains a Buffer Overflow vulnerability in AQL (Antelope Query Language) database engine that can result in
<= 4.1
An issue was discovered in Contiki-NG through 4.1. There is a buffer over-read in lookup in os/storage/antelope/lvm.c while parsin
<= 4.1
An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in next_string in os/storage/antelope/aq
<= 4.1
An issue was discovered in Contiki-NG through 4.1. There is a buffer overflow while parsing AQL in lvm_shift_for_operator in os/st
<= 4.1
An issue was discovered in Contiki-NG through 4.1. There is a buffer overflow in lvm_set_type in os/storage/antelope/lvm.c while p
<= 4.1
An issue was discovered in Contiki-NG through 4.1. There is a stack-based buffer overflow in parse_relations in os/storage/antelop