libcoap records
18 published records for vendor libcoap.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 88.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-476 NULL Pointer Dereference7
- CWE-125 Out-of-bounds Read4
- CWE-121 Stack-based Buffer Overflow2
- CWE-195 Signed to Unsigned Conversion Error1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-190 Integer Overflow or Wraparound1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2026-29013No exploit | libcoap Out-of-Bounds Read in OSCORE CBOR Unwrap Handlinglibcoap · libcoap · CWE-125 | High8.8 | — | 0.5% | Apr 17, 2026 |
32Monitor | CVE-2025-34468No exploit | libcoap Stack-Based Buffer Overflow in Address Resolution DoS or Potential RCElibcoap · libcoap · CWE-121 | High8.2 | — | 0.7% | Dec 31, 2025 |
31Monitor | CVE-2024-0962No exploit | obgm libcoap Configuration File coap_oscore.c get_split_entry stack-based overflowlibcoap · libcoap · CWE-121 | High7.8 | — | 0.8% | Jan 27, 2024 |
30Monitor | CVE-2024-31031No exploit | An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integelibcoap · libcoap · CWE-190 | High7.5 | — | 0.9% | Apr 17, 2024 |
30Monitor | CVE-2023-30362No exploit | Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 allows attackers to oblibcoap · libcoap · CWE-125 | High7.5 | — | 0.8% | Jun 23, 2023 |
30Monitor | CVE-2023-51847No exploit | An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_CWE-400 | High7.5 | — | 0.6% | Jun 6, 2024 |
30Monitor | CVE-2024-46304No exploit | A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_requestCWE-120 | High7.5 | — | 0.6% | Oct 9, 2024 |
30Monitor | CVE-2025-65493No exploit | NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLSlibcoap · libcoap · CWE-476 | High7.5 | — | 0.4% | Nov 24, 2025 |
30Monitor | CVE-2025-65495No exploit | Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of libcoap · libcoap · CWE-195 | High7.5 | — | 0.2% | Nov 24, 2025 |
30Monitor | CVE-2025-65494No exploit | NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial libcoap · libcoap · CWE-476 | High7.5 | — | 0.2% | Nov 24, 2025 |
26Monitor | CVE-2023-35862No exploit | libcoap 4.3.1 contains a buffer over-read via the function coap_parse_oscore_conf_mem at coap_oscore.c.libcoap · libcoap · CWE-125 | Medium6.5 | — | 0.8% | Jun 19, 2023 |
26Monitor | CVE-2025-59391No exploit | A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches.libcoap · libcoap · CWE-125 | Medium6.5 | — | 0.3% | Dec 8, 2025 |
17Monitor | CVE-2025-65497No exploit | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denialibcoap · libcoap · CWE-476 | Medium4.3 | — | 0.3% | Nov 24, 2025 |
17Monitor | CVE-2025-65498No exploit | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denialibcoap · libcoap · CWE-476 | Medium4.3 | — | 0.3% | Nov 24, 2025 |
17Monitor | CVE-2025-65496No exploit | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denialibcoap · libcoap · CWE-476 | Medium4.3 | — | 0.3% | Nov 24, 2025 |
17Monitor | CVE-2025-65500No exploit | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denialibcoap · libcoap · CWE-476 | Medium4.3 | — | 0.3% | Nov 24, 2025 |
17Monitor | CVE-2025-65501No exploit | Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS libcoap · libcoap · CWE-476 | Medium4.3 | — | 0.3% | Nov 24, 2025 |
17Monitor | CVE-2025-65499No exploit | Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of servicelibcoap · libcoap · CWE-129 | Medium4.3 | — | 0.3% | Nov 24, 2025 |
- CVE-2026-2901335Monitor
libcoap Out-of-Bounds Read in OSCORE CBOR Unwrap Handling
HighCVSS 8.8No exploitEPSS 1%libcoap · libcoapApr 17, 2026
- CVE-2025-3446832Monitor
libcoap Stack-Based Buffer Overflow in Address Resolution DoS or Potential RCE
HighCVSS 8.2No exploitEPSS 1%libcoap · libcoapDec 31, 2025
- CVE-2024-096231Monitor
obgm libcoap Configuration File coap_oscore.c get_split_entry stack-based overflow
HighCVSS 7.8No exploitEPSS 1%libcoap · libcoapJan 27, 2024
- CVE-2024-3103130Monitor
An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned intege
HighCVSS 7.5No exploitEPSS 1%libcoap · libcoapApr 17, 2024
- CVE-2023-3036230Monitor
Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 allows attackers to ob
HighCVSS 7.5No exploitEPSS 1%libcoap · libcoapJun 23, 2023
- CVE-2023-5184730Monitor
An issue in obgm and Libcoap v.a3ed466 allows a remote attacker to cause a denial of service via thecoap_context_t function in the src/coap_
HighCVSS 7.5No exploitEPSS 1%Jun 6, 2024
- CVE-2024-4630430Monitor
A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request
HighCVSS 7.5No exploitEPSS 1%Oct 9, 2024
- CVE-2025-6549330Monitor
NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS
HighCVSS 7.5No exploitEPSS 0%libcoap · libcoapNov 24, 2025
- CVE-2025-6549530Monitor
Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of
HighCVSS 7.5No exploitEPSS 0%libcoap · libcoapNov 24, 2025
- CVE-2025-6549430Monitor
NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial
HighCVSS 7.5No exploitEPSS 0%libcoap · libcoapNov 24, 2025
- CVE-2023-3586226Monitor
libcoap 4.3.1 contains a buffer over-read via the function coap_parse_oscore_conf_mem at coap_oscore.c.
MediumCVSS 6.5No exploitEPSS 1%libcoap · libcoapJun 19, 2023
- CVE-2025-5939126Monitor
A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches.
MediumCVSS 6.5No exploitEPSS 0%libcoap · libcoapDec 8, 2025
- CVE-2025-6549717Monitor
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denia
MediumCVSS 4.3No exploitEPSS 0%libcoap · libcoapNov 24, 2025
- CVE-2025-6549817Monitor
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denia
MediumCVSS 4.3No exploitEPSS 0%libcoap · libcoapNov 24, 2025
- CVE-2025-6549617Monitor
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denia
MediumCVSS 4.3No exploitEPSS 0%libcoap · libcoapNov 24, 2025
- CVE-2025-6550017Monitor
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denia
MediumCVSS 4.3No exploitEPSS 0%libcoap · libcoapNov 24, 2025
- CVE-2025-6550117Monitor
Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS
MediumCVSS 4.3No exploitEPSS 0%libcoap · libcoapNov 24, 2025
- CVE-2025-6549917Monitor
Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service
MediumCVSS 4.3No exploitEPSS 0%libcoap · libcoapNov 24, 2025