Vulnerabilidades em NASA

45 resultados
Análise Vexday

A NASA apresenta um perfil de risco baixo com apenas 12 CVEs catalogadas e nenhuma sob ataque ativo confirmado. Duas vulnerabilidades foram divulgadas nos últimos 90 dias, sem críticas de severidade máxima, sendo a fraqueza dominante relacionada a buffer overflow (CWE-119), indicando necessidade de revisão em controles de memória mas sem pressão imediata de exploração.

CVE-2026-21900HIGHCryptoLib Has Out-of-Bounds Read in KMC Encrypt Metadata Parsing via Flawed strtok PatternEPSS 0.6%CVE-2026-22023HIGHCryptoLib Has Out-of-Bounds Read in KMC AEAD Encrypt Metadata Parsing via Flawed strtok PatternEPSS 0.6%CVE-2026-79954HIGHNASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCIDEPSS 0.6%CVE-2026-22025MEDIUMCryptoLib Memory Leak on HTTP Error Response in KMC ClientEPSS 0.5%CVE-2026-82478MEDIUMNASA Trick TCP Socket JSONVariableServerThread.cpp parse_request stack-based overflowEPSS 0.5%CVE-2025-46672LOWNASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.EPSS 0.5%CVE-2026-22697HIGHCryptoLib Has Heap Buffer Overflow Vulnerability in KMC Base64 Decode Handling (KMC JSON base64ciphertext/base64cleartext)EPSS 0.5%CVE-2025-46673MEDIUMNASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space DEPSS 0.5%CVE-2025-29910MEDIUMCryptoLib's crypto_handle_incrementing_nontransmitted_counter Function has Memory LeakEPSS 0.5%CVE-2026-22024MEDIUMCryptoLib Memory Leak in KMC Encrypt Function Leads to Resource ExhaustionEPSS 0.5%CVE-2026-82802MEDIUMNASA earthdata-search granules Endpoint handler.js OpenSearchGranuleSearchLambda server-side request forgeryEPSS 0.5%CVE-2025-64096HIGHCryptoLib vulnerable to Stack Buffer Overflow in Crypto_Key_Update due to missing TLV length checkEPSS 0.5%CVE-2026-82801MEDIUMNASA earthdata-search scale Endpoint handler.js scaleImage server-side request forgeryEPSS 0.5%CVE-2026-21898HIGHCryptoLib Has Out-of-bounds Read in Crypto_AOS_ProcessSecurityEPSS 0.5%CVE-2025-54878HIGHHeap Buffer Overflow in NASA CryptoLib 1.4.0 `Crypto_TC_Check_IV_Setup`EPSS 0.4%CVE-2026-82479MEDIUMNASA cFS SBN TCP sbn_tcp_if.c OS_read buffer overflowEPSS 0.4%CVE-2026-82480MEDIUMNASA cFS cFE Software Bus cfe_sb_util.c CFE_SB_GetUserDataLength integer underflowEPSS 0.4%CVE-2026-5473LOWNASA cFS Pickle pickle.load deserializationEPSS 0.4%CVE-2025-46675LOWIn NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.EPSS 0.4%CVE-2026-21899MEDIUMCryptoLib has an out-of-bounds read and crash vulnerability when decoding an empty Base64url stringEPSS 0.4%