Vulnerabilities in nasa

45 results
Vexday analysis

A NASA apresenta 24 vulnerabilidades catalogadas na base do Vexday, com apenas 2 classificadas como críticas e nenhuma sob ataque ativo atualmente. O risco é caracterizado principalmente por fraquezas de escrita fora dos limites (CWE-122), sem novos CVEs publicados nos últimos 90 dias, indicando um cenário de exposições históricas e não emergentes.

CVE-2019-1010060—NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code fEPSS 7.2%CVE-2018-3847HIGHMultiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially craEPSS 2.8%CVE-2025-30216CRITICALCryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header LengthEPSS 2.6%CVE-2026-72577CRITICALNASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command InjectionEPSS 1.3%CVE-2025-29912HIGHCryptoLib Has Heap Buffer Overflow Due to Unsigned Integer Underflow in Crypto_TC_ProcessSecurityEPSS 1.1%CVE-2026-72579HIGHNASA HyperCP - OS Command Injection via Malicious HTTP Response from Data ServerEPSS 1.1%CVE-2025-29909HIGHCryptoLib's Crypto_TC_ApplySecurity() Has a Heap Buffer Overflow VulnerabilityEPSS 1.1%CVE-2025-59534HIGHCryptoLib command Injection vulnerability in initialize_kerberos_keytab_file_login()EPSS 0.9%CVE-2026-41144NONEF´ (F Prime) has Integer Overflow in FileUplinkEPSS 0.8%CVE-2025-29911HIGHCryptoLib Has Heap Buffer Overflow in Crypto_AOS_ProcessSecurity FunctionEPSS 0.7%CVE-2025-29913HIGHCryptoLib's Crypto_TC_Prep_AAD Has Buffer Overflow Due to Integer UnderflowEPSS 0.7%CVE-2025-30356CRITICALHeap Buffer Overflow via Incomplete Length Check in `Crypto_TC_ApplySecurity`EPSS 0.6%CVE-2022-23053MEDIUMOpenmct XSS via the “Condition Widget”EPSS 0.6%CVE-2022-23054MEDIUMOpenmct XSS via the “Summary Widget”EPSS 0.6%CVE-2022-22126MEDIUMOpenmct XSS via the “Web Page” elementEPSS 0.6%CVE-2026-22026HIGHCryptoLib Unbounded Memory Allocation in KMC HTTP Response Handler Allows Resource ExhaustionEPSS 0.6%CVE-2026-5474MEDIUMNASA cFS CCSDS Packet Header to_lab_passthru_encode.c CFE_MSG_GetSize heap-based overflowEPSS 0.6%CVE-2026-18064HIGHNASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer DereferenceEPSS 0.6%CVE-2026-15352HIGHNASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer DereferenceEPSS 0.6%CVE-2025-46674LOWNASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading tEPSS 0.6%