<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:38:56 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-01281</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-01281</link>
      <description>bdu:2020-01281</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-01281</guid>
    </item>
    <item>
      <title>certfr-2019-avi-367 — De multiples vulnérabilités ont été découvertes dans la pile réseau
IPnet (utilisée notamment par Wind River VxWorks).…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2019-avi-367</link>
      <description>certfr-2019-avi-367</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2019-avi-367</guid>
    </item>
    <item>
      <title>cnvd-2019-25700</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-25700</link>
      <description>cnvd-2019-25700</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-25700</guid>
    </item>
    <item>
      <title>EUVD-2026-54916</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-54916</link>
      <description>EUVD-2026-54916</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-54916</guid>
    </item>
    <item>
      <title>fkie_cve-2019-12255</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-12255</link>
      <description>&lt;p&gt;Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-12255</guid>
    </item>
    <item>
      <title>GHSA-h297-57pm-6g4c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h297-57pm-6g4c</link>
      <description>&lt;p&gt;Wind River VxWorks 6.5 through 6.9.3 has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. Affected versions: 6.6, 6.7, 6.8, 6.9&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Wind River VxWorks 6.5 through 6.9.3 has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. Affected versions: 6.6, 6.7, 6.8, 6.9&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h297-57pm-6g4c</guid>
    </item>
    <item>
      <title>gsd-2019-12255</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-12255</link>
      <description>gsd-2019-12255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-12255</guid>
    </item>
    <item>
      <title>ICSA-19-211-01 — Wind River VxWorks (Update A)</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-19-211-01</link>
      <description>&lt;p&gt;This vulnerability resides in the IPv4 option parsing and may be triggered by IPv4 packets containing invalid options. The most likely outcome of triggering this defect is that the tNet0 task crashes. This vulnerability can result in remote code execution. DHCP packets may go past the local area network (LAN) via DHCP-relays, but are otherwise confined to the LAN. The DHCP-client may be used by VxWorks and in the bootrom. Bootrom, using DHCP/BOOTP, is only vulnerable during the boot-process. This vulnerability may be used to overwrite the heap, which could result in a later crash when a task requests memory from the heap. This vulnerability can result in remote code execution. An attacker can either hijack an existing TCP-session and inject bad TCP-segments or establish a new TCP-session on any TCP-port listened to by the target. This vulnerability could lead to a buffer overflow of up to a full TCP receive-window (by default, 10k-64k depending on version). The buffer overflow occurs in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP-window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution. This vulnerability could lead to a buffer overflow of up to a full TCP receive-window (by default, 10k-64k depending on…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This vulnerability resides in the IPv4 option parsing and may be triggered by IPv4 packets containing invalid options. The most likely outcome of triggering this defect is that the tNet0 task crashes. This vulnerability can result in remote code execution. DHCP packets may go past the local area network (LAN) via DHCP-relays, but are otherwise confined to the LAN. The DHCP-client may be used by VxWorks and in the bootrom. Bootrom, using DHCP/BOOTP, is only vulnerable during the boot-process. This vulnerability may be used to overwrite the heap, which could result in a later crash when a task requests memory from the heap. This vulnerability can result in remote code execution. An attacker can either hijack an existing TCP-session and inject bad TCP-segments or establish a new TCP-session on any TCP-port listened to by the target. This vulnerability could lead to a buffer overflow of up to a full TCP receive-window (by default, 10k-64k depending on version). The buffer overflow occurs in the task calling recv()/recvfrom()/recvmsg(). Applications that pass a buffer equal to or larger than a full TCP-window are not susceptible to this attack. Applications passing a stack-allocated variable as a buffer are the easiest to exploit. The most likely outcome is a crash of the application reading from the affected socket, which could result in remote code execution. This vulnerability could lead to a buffer overflow of up to a full TCP receive-window (by default, 10k-64k depending on…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-19-211-01</guid>
    </item>
    <item>
      <title>VDE-2020-002 — PHOENIX CONTACT: Advisory for multiple FL Switch GHS utilising VxWorks</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2020-002</link>
      <description>&lt;p&gt;CVS-2019-12255&lt;/p&gt;
&lt;p&gt;Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.&lt;/p&gt;
&lt;p&gt;The vulnerability affects a little-known feature of the TCP/IP protocol, sending out-of-band data, also known as urgent data. Although the feature is rarely used in the real world, its implementation, consisting of an &amp;#39;Urgent Flag&amp;#39; and an &amp;#39;Urgent Pointer&amp;#39;, is present in the header of every TCP packet. Exploiting these vulnerabilities does therefore not depend on any specific configuration. If a VxWorks device communicates using the TCP protocol, it is vulnerable. It also does not matter which side initiates a TCP connection. An attacker can exploit the vulnerabilities if the VxWorks device is operated as a server that accepts TCP connections, if the VxWorks device connects to a malicious host operated by the attacker, or as a man-in-the-middle, manipulating a TCP connection between the VxWorks device and a legitimate host.&lt;/p&gt;
&lt;p&gt;CVE-2019-12258&lt;/p&gt;
&lt;p&gt;This vulnerability affects established TCP sessions. An attacker who can figure out the source and destination TCP port and IP addresses of a session can inject invalid TCP segments into the flow, causing the TCP session to be reset.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CVS-2019-12255&lt;/p&gt;
&lt;p&gt;Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.&lt;/p&gt;
&lt;p&gt;The vulnerability affects a little-known feature of the TCP/IP protocol, sending out-of-band data, also known as urgent data. Although the feature is rarely used in the real world, its implementation, consisting of an &amp;#39;Urgent Flag&amp;#39; and an &amp;#39;Urgent Pointer&amp;#39;, is present in the header of every TCP packet. Exploiting these vulnerabilities does therefore not depend on any specific configuration. If a VxWorks device communicates using the TCP protocol, it is vulnerable. It also does not matter which side initiates a TCP connection. An attacker can exploit the vulnerabilities if the VxWorks device is operated as a server that accepts TCP connections, if the VxWorks device connects to a malicious host operated by the attacker, or as a man-in-the-middle, manipulating a TCP connection between the VxWorks device and a legitimate host.&lt;/p&gt;
&lt;p&gt;CVE-2019-12258&lt;/p&gt;
&lt;p&gt;This vulnerability affects established TCP sessions. An attacker who can figure out the source and destination TCP port and IP addresses of a session can inject invalid TCP segments into the flow, causing the TCP session to be reset.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2020-002</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2884 — Wind River VxWorks: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2884</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Wind River VxWorks ausnutzen, um dadurch die Integrität, Vertraulichkeit und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Wind River VxWorks ausnutzen, um dadurch die Integrität, Vertraulichkeit und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2884</guid>
    </item>
  </channel>
</rss>
