ccn-lite records
17 published records for vendor ccn-lite.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-190 Integer Overflow or Wraparound2
- CWE-772 Missing Release of Resource after Effective Lifetime2
- CWE-476 NULL Pointer Dereference2
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-12468No exploit | Buffer overflow in ccn-lite-ccnb2xml.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors invccn-lite · ccn-lite · CWE-119 | Critical9.8 | — | 1.9% | Feb 7, 2018 |
40Plan | CVE-2017-12469No exploit | Buffer overflow in util/ccnl-common.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging inccn-lite · ccn-lite · CWE-119 | Critical9.8 | — | 1.9% | Feb 7, 2018 |
40Plan | CVE-2017-12466No exploit | CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors related to ssl_halen when running ccn-lite-siccn-lite · ccn-lite · CWE-119 | Critical9.8 | — | 1.8% | Feb 7, 2018 |
40Plan | CVE-2017-12472No exploit | ccnl-ext-mgmt.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging missing NULL pointer checcn-lite · ccn-lite · CWE-476 | Critical9.8 | — | 1.8% | Feb 7, 2018 |
40Plan | CVE-2017-12471No exploit | The cnb_parse_lev function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging failure to chccn-lite · ccn-lite · CWE-119 | Critical9.8 | — | 1.8% | Feb 7, 2018 |
40Plan | CVE-2017-12465No exploit | Multiple integer overflows in CCN-lite before 2.00 allow context-dependent attackers to have unspecified impact via vectors involving the (1ccn-lite · ccn-lite · CWE-190 | Critical9.8 | — | 1.8% | Feb 7, 2018 |
39Monitor | CVE-2017-12470No exploit | Integer overflow in the ndn_parse_sequence function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact viccn-lite · ccn-lite · CWE-190 | Critical9.8 | — | 1.5% | Feb 7, 2018 |
39Monitor | CVE-2018-6948No exploit | In CCN-lite 2, the function ccnl_prefix_to_str_detailed can cause a buffer overflow, when writing a prefix to the buffer buf.ccn-lite · ccn-lite · CWE-119 | Critical9.8 | — | 1.5% | Feb 13, 2018 |
39Monitor | CVE-2018-6953No exploit | In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual component length, which haccn-lite · ccn-lite · CWE-119 | Critical9.8 | — | 1.5% | Feb 13, 2018 |
39Monitor | CVE-2018-7039No exploit | CCN-lite 2.0.0 Beta allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact becauseccn-lite · ccn-lite · CWE-119 | Critical9.8 | — | 1.4% | Feb 14, 2018 |
39Monitor | CVE-2018-12889No exploit | An issue was discovered in CCN-lite 2.0.1.ccn-lite · ccn-lite · CWE-787 | Critical9.8 | — | 1.3% | Jun 26, 2018 |
35Monitor | CVE-2018-6480No exploit | A type confusion issue was discovered in CCN-lite 2, leading to a memory access violation and a failure of the nonce feature (which, for exaccn-lite · ccn-lite · CWE-704 | High8.8 | — | 1.3% | Jan 31, 2018 |
31Monitor | CVE-2017-12412No exploit | ccn-lite-ccnb2xml in CCN-lite before 2.0.0 allows context-dependent attackers to have unspecified impact via a crafted file, which triggers ccn-lite · ccn-lite · CWE-835 | High7.8 | — | 1.3% | Feb 7, 2018 |
30Monitor | CVE-2017-12467No exploit | Memory leak in CCN-lite before 2.00 allows context-dependent attackers to cause a denial of service (memory consumption) by leveraging failuccn-lite · ccn-lite · CWE-772 | High7.5 | — | 1.5% | Feb 7, 2018 |
30Monitor | CVE-2017-12464No exploit | ccn-lite-valid.c in CCN-lite before 2.00 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via vectccn-lite · ccn-lite · CWE-476 | High7.5 | — | 1.5% | Feb 7, 2018 |
30Monitor | CVE-2017-12463No exploit | Memory leak in the ccnl_app_RX function in ccnl-uapi.c in CCN-lite before 2.00 allows context-dependent attackers to cause a denial of serviccn-lite · ccn-lite · CWE-772 | High7.5 | — | 1.4% | Feb 7, 2018 |
30Monitor | CVE-2017-12473No exploit | ccnl_ccntlv_bytes2pkt in CCN-lite allows context-dependent attackers to cause a denial of service (application crash) via vectors involving ccn-lite · ccn-lite · CWE-20 | High7.5 | — | 1.3% | Feb 7, 2018 |
- CVE-2017-1246840Plan
Buffer overflow in ccn-lite-ccnb2xml.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors inv
CriticalCVSS 9.8No exploitEPSS 2%ccn-lite · ccn-liteFeb 7, 2018
- CVE-2017-1246940Plan
Buffer overflow in util/ccnl-common.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging in
CriticalCVSS 9.8No exploitEPSS 2%ccn-lite · ccn-liteFeb 7, 2018
- CVE-2017-1246640Plan
CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors related to ssl_halen when running ccn-lite-si
CriticalCVSS 9.8No exploitEPSS 2%ccn-lite · ccn-liteFeb 7, 2018
- CVE-2017-1247240Plan
ccnl-ext-mgmt.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging missing NULL pointer che
CriticalCVSS 9.8No exploitEPSS 2%ccn-lite · ccn-liteFeb 7, 2018
- CVE-2017-1247140Plan
The cnb_parse_lev function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging failure to ch
CriticalCVSS 9.8No exploitEPSS 2%ccn-lite · ccn-liteFeb 7, 2018
- CVE-2017-1246540Plan
Multiple integer overflows in CCN-lite before 2.00 allow context-dependent attackers to have unspecified impact via vectors involving the (1
CriticalCVSS 9.8No exploitEPSS 2%ccn-lite · ccn-liteFeb 7, 2018
- CVE-2017-1247039Monitor
Integer overflow in the ndn_parse_sequence function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact vi
CriticalCVSS 9.8No exploitEPSS 2%ccn-lite · ccn-liteFeb 7, 2018
- CVE-2018-694839Monitor
In CCN-lite 2, the function ccnl_prefix_to_str_detailed can cause a buffer overflow, when writing a prefix to the buffer buf.
CriticalCVSS 9.8No exploitEPSS 2%ccn-lite · ccn-liteFeb 13, 2018
- CVE-2018-695339Monitor
In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual component length, which ha
CriticalCVSS 9.8No exploitEPSS 2%ccn-lite · ccn-liteFeb 13, 2018
- CVE-2018-703939Monitor
CCN-lite 2.0.0 Beta allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact because
CriticalCVSS 9.8No exploitEPSS 1%ccn-lite · ccn-liteFeb 14, 2018
- CVE-2018-1288939Monitor
An issue was discovered in CCN-lite 2.0.1.
CriticalCVSS 9.8No exploitEPSS 1%ccn-lite · ccn-liteJun 26, 2018
- CVE-2018-648035Monitor
A type confusion issue was discovered in CCN-lite 2, leading to a memory access violation and a failure of the nonce feature (which, for exa
HighCVSS 8.8No exploitEPSS 1%ccn-lite · ccn-liteJan 31, 2018
- CVE-2017-1241231Monitor
ccn-lite-ccnb2xml in CCN-lite before 2.0.0 allows context-dependent attackers to have unspecified impact via a crafted file, which triggers
HighCVSS 7.8No exploitEPSS 1%ccn-lite · ccn-liteFeb 7, 2018
- CVE-2017-1246730Monitor
Memory leak in CCN-lite before 2.00 allows context-dependent attackers to cause a denial of service (memory consumption) by leveraging failu
HighCVSS 7.5No exploitEPSS 2%ccn-lite · ccn-liteFeb 7, 2018
- CVE-2017-1246430Monitor
ccn-lite-valid.c in CCN-lite before 2.00 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via vect
HighCVSS 7.5No exploitEPSS 2%ccn-lite · ccn-liteFeb 7, 2018
- CVE-2017-1246330Monitor
Memory leak in the ccnl_app_RX function in ccnl-uapi.c in CCN-lite before 2.00 allows context-dependent attackers to cause a denial of servi
HighCVSS 7.5No exploitEPSS 1%ccn-lite · ccn-liteFeb 7, 2018
- CVE-2017-1247330Monitor
ccnl_ccntlv_bytes2pkt in CCN-lite allows context-dependent attackers to cause a denial of service (application crash) via vectors involving
HighCVSS 7.5No exploitEPSS 1%ccn-lite · ccn-liteFeb 7, 2018