Skip to content
Noroxi

dronecode records

26 published records for vendor dronecode.

All records

26 records
  • RVD#3316: No authentication in MAVLink protocol

    CriticalCVSS 9.8No exploitEPSS 2%

    dronecode · micro air vehicle linkJul 3, 2020

  • RVD#3317: MAVLink version handshaking allows for an attacker to bypass authentication

    CriticalCVSS 9.8No exploitEPSS 1%

    dronecode · micro air vehicle linkAug 20, 2020

  • PX4-Autopilot Heap Buffer Overflow Bug

    CriticalCVSS 9.8No exploitEPSS 1%

    dronecode · px4 drone autopilotOct 31, 2023

  • PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packet

    HighCVSS 8.1No exploitEPSS 0%

    dronecode · px4 drone autopilotMar 16, 2026

  • PX4 Autopilot versions 1.12.x through 1.15.x contain a protection mechanism failure in the "Re-arm Grace Period" logic.

    HighCVSS 8.1No exploitEPSS 0%

    dronecode · px4 drone autopilotMar 10, 2026

  • PX4 Autopilot versions 1.12.x through 1.15.x contain a logic flaw in the mode switching mechanism.

    HighCVSS 8.1No exploitEPSS 0%

    dronecode · px4 drone autopilotMar 10, 2026

  • Zenoh uORB Subscriber Allows Arbitrary Stack Allocation (PX4/PX4-Autopilot)

    HighCVSS 8.0No exploitEPSS 0%

    dronecode · px4 drone autopilotMar 16, 2026

  • Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the progr

    HighCVSS 7.9No exploitEPSS 0%

    dronecode · px4 drone autopilotJan 7, 2025

  • An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive information via vario

    HighCVSS 7.5No exploitEPSS 1%

    yuneec · mantis q firmwareMar 9, 2023

  • Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.

    HighCVSS 7.5No exploitEPSS 1%

    dronecode · px4 drone autopilotJul 6, 2023

  • RVD#3315: Cleartext transmission of sensitive information in MAVLink protocol version 1.0 and 2.0

    HighCVSS 7.5No exploitEPSS 1%

    dronecode · micro air vehicle linkJul 3, 2020

  • PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.

    HighCVSS 7.5No exploitEPSS 1%

    dronecode · px4 drone autopilotJun 25, 2024

  • PX4 Autopilot MAVLink FTP Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete)

    MediumCVSS 6.8No exploitEPSS 0%

    dronecode · px4 drone autopilotMar 16, 2026

  • PX4 autopilot BST Device Name Length Can Overflow Driver Buffer

    MediumCVSS 6.8No exploitEPSS 0%

    dronecode · px4 drone autopilotMar 16, 2026

  • A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.

    MediumCVSS 6.5No exploitEPSS 1%

    dronecode · px4 drone autopilotJun 25, 2024

  • PX4 Autopilot: Stack-based Buffer Overflow via Oversized Path Input in MAVLink Log Request Handling

    MediumCVSS 6.5Proof of conceptEPSS 0%

    dronecode · px4 drone autopilotMar 18, 2026

  • PX4 Autopilot MAVLink FTP Session Validation Logic Error Allows Operations on Invalid File Descriptors

    MediumCVSS 6.5No exploitEPSS 0%

    dronecode · px4 drone autopilotMar 16, 2026

  • An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone via the home point loc

    MediumCVSS 6.6No exploitEPSS 0%

    dronecode · px4 drone autopilotApr 10, 2024

  • PX4 autopilot has a stack buffer overflow in tattu_can due to unbounded memcpy in frame assembly loop

    MediumCVSS 6.1Proof of conceptEPSS 0%

    dronecode · px4 drone autopilotMar 16, 2026

  • PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the function.

    MediumCVSS 5.6No exploitEPSS 0%

    dronecode · px4 drone autopilotApr 23, 2024

  • PX4 autopilot has a heap Use-After-Free in MavlinkShell::available() via SERIAL_CONTROL Race Condition

    MediumCVSS 5.3No exploitEPSS 0%

    dronecode · px4 drone autopilotMar 16, 2026

  • PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflow

    MediumCVSS 4.8No exploitEPSS 0%

    dronecode · px4 drone autopilotDec 28, 2025

  • Global Buffer Overflow leading to denial of service in PX4-Autopilot

    MediumCVSS 4.3No exploitEPSS 1%

    dronecode · px4 drone autopilotNov 13, 2023

  • An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach R

    MediumCVSS 4.4No exploitEPSS 0%

    dronecode · px4 drone autopilotApr 21, 2024

  • PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability i

    MediumCVSS 4.2No exploitEPSS 0%

    dronecode · px4 drone autopilotFeb 6, 2024