CVEs we hold for Contiki-ng
Records whose assigning authority named Contiki-ng as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-5857Contiki-NG MQTT Client Out-of-Bounds Write in PUBLISH Topic Parser via Persistent State Between TCP SegmentsContiki-NG CVE-2026-5856Contiki-NG DNS/mDNS Resolver Out-of-Bounds Read via Unchecked skip_name Traversal Before Transaction-ID ValidationContiki-NG CVE-2026-5855Contiki-NG LwM2M TLV Parser Out-of-Bounds Read via Unchecked Buffer Length in lwm2m_tlv_readContiki-NG CVE-2024-47181Unaligned memory access in RPL option processing in Contiki-NGcontiki-ng CVE-2024-41126Out-of-bounds read when decoding SNMP messages in Contiki-NGcontiki-ng CVE-2024-41125Out-of-bounds read in SNMP when decoding a string in Contiki-NGcontiki-ng CVE-2023-50927Insufficient boundary checks for DIO and DAO messages in RPL-Lite in Contiki-NGcontiki-ng CVE-2023-50926Unvalidated DIO prefix info length in RPL-Lite in Contiki-NGcontiki-ng CVE-2023-48229Out-of-bounds write in the radio driver for Contiki-NG nRF platformscontiki-ng CVE-2023-37459Out-of-bounds read when processing a received IPv6 packetcontiki-ng CVE-2023-37281Out-of-bounds read during IPHC address decompressioncontiki-ng CVE-2023-34101Contiki-NG vulnerable to out-of-bounds read when processing ICMP DAO inputcontiki-ng CVE-2023-31129Contiki-NG missing NULL pointer check in IPv6 neighbor discoverycontiki-ng CVE-2023-30546Contiki-NG has off-by-one error in Antelope DBMScontiki-ng CVE-2023-29001Uncontrolled recursion due to insufficient validation of the IPv6 source routing header in Contiki-NGcontiki-ng CVE-2023-28116Buffer overflow in L2CAP due to misconfigured MTUcontiki-ng CVE-2023-23609contiki-ng BLE-L2CAP contains Improper size validation of L2CAP framescontiki-ng CVE-2022-41972Contiki-NG contains NULL Pointer Dereference in BLE L2CAP modulecontiki-ng CVE-2022-41873Out-of-bounds read and write in BLE L2CAP modulecontiki-ng CVE-2022-36054Out-of-bounds write when decompressing 6LoWPAN payload in Contiki-NGcontiki-ng CVE-2022-36052Out-of-bounds read when decompressing UDP headercontiki-ng CVE-2022-35927Unverified DIO prefix info lengths in RPL-Classic in Contiki-NGcontiki-ng CVE-2022-35926Out-of-bounds read in IPv6 neighbor solicitation in Contiki-NGcontiki-ng CVE-2021-21410Out-of-bounds read in the 6LoWPAN implementationcontiki-ng CVE-2021-21282Buffer overflow in RPL source routing header processingcontiki-ng CVE-2021-21281Buffer overflow due to unvalidated TCP data offsetcontiki-ng CVE-2021-21280Out-of-bounds write when processing 6LoWPAN extension headerscontiki-ng CVE-2021-21279Infinite loop in IPv6 neighbor solicitation processingcontiki-ng CVE-2021-21257Out-of-bounds write in RPL-Classic and RPL-Litecontiki-ng 32 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.