Home/Product/contiki os contiki
Product

contiki os contiki

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-40523
all versions
In Contiki 3.0, Telnet option negotiation is mishandled. During negotiation between a server and a client, the server may fail to
7.5HIGH
CVE-2021-38387
all versions
In Contiki 3.0, a Telnet server that silently quits (before disconnection with clients) leads to connected clients entering an inf
7.5HIGH
CVE-2021-38386
all versions
In Contiki 3.0, a buffer overflow in the Telnet service allows remote attackers to cause a denial of service because the ls comman
7.5HIGH
CVE-2021-38311
all versions
In Contiki 3.0, potential nonterminating acknowledgment loops exist in the Telnet service. When the negotiated options are already
7.5HIGH
CVE-2021-28362
<= 3.0
An issue was discovered in Contiki through 3.0. When sending an ICMPv6 error message because of invalid extension header options i
7.5HIGH
CVE-2020-25112
<= 3.0
An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extension lengths.
9.8CRITICAL
CVE-2020-25111
<= 3.0
An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header length. This
9.8CRITICAL
CVE-2020-24336
<= 3.0
An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64
9.8CRITICAL
CVE-2020-13986
<= 3.0
An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when handling RPL extens
7.5HIGH
CVE-2020-13985
<= 3.0
An issue was discovered in Contiki through 3.0. A memory corruption vulnerability exists in the uIP TCP/IP stack component when ha
7.5HIGH
CVE-2020-13984
<= 3.0
An issue was discovered in Contiki through 3.0. An infinite loop exists in the uIP TCP/IP stack component when processing IPv6 ext
7.5HIGH
CVE-2019-9183
<= 3.0
An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. A buffer overflow is present due to an integer underflo
7.5HIGH
CVE-2019-8359
<= 3.0
An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. An out of bounds write is present in the data section d
9.8CRITICAL
CVE-2017-7296
all versions
An issue was discovered in Contiki Operating System 3.0. A Persistent XSS vulnerability is present in the MQTT/IBM Cloud Config pa
6.1MEDIUM
CVE-2017-7295
all versions
An issue was discovered in Contiki Operating System 3.0. A use-after-free vulnerability exists in httpd-simple.c in cc26xx-web-dem
7.5HIGH
threatengine.sh