Vulnerabilidades em nasa

39 resultados
Análise Vexday

A NASA apresenta 24 vulnerabilidades catalogadas na base do Vexday, com apenas 2 classificadas como críticas e nenhuma sob ataque ativo atualmente. O risco é caracterizado principalmente por fraquezas de escrita fora dos limites (CWE-122), sem novos CVEs publicados nos últimos 90 dias, indicando um cenário de exposições históricas e não emergentes.

CVE-2025-46673MEDIUMNASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space DEPSS 0.5%CVE-2025-29910MEDIUMCryptoLib's crypto_handle_incrementing_nontransmitted_counter Function has Memory LeakEPSS 0.5%CVE-2026-22024MEDIUMCryptoLib Memory Leak in KMC Encrypt Function Leads to Resource ExhaustionEPSS 0.4%CVE-2026-15352HIGHNASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer DereferenceEPSS 0.4%CVE-2026-41144NONEF´ (F Prime) has Integer Overflow in FileUplinkEPSS 0.4%CVE-2026-21898HIGHCryptoLib Has Out-of-bounds Read in Crypto_AOS_ProcessSecurityEPSS 0.4%CVE-2025-54878HIGHHeap Buffer Overflow in NASA CryptoLib 1.4.0 `Crypto_TC_Check_IV_Setup`EPSS 0.4%CVE-2026-5474MEDIUMNASA cFS CCSDS Packet Header to_lab_passthru_encode.c CFE_MSG_GetSize heap-based overflowEPSS 0.4%CVE-2026-18064HIGHNASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer DereferenceEPSS 0.3%CVE-2025-46675LOWIn NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.EPSS 0.3%CVE-2026-21899MEDIUMCryptoLib has an out-of-bounds read and crash vulnerability when decoding an empty Base64url stringEPSS 0.3%CVE-2026-21897HIGHCryptoLib Has Out-of-Bounds Write in Crypto_Config_Add_Gvcid_Managed_ParametersEPSS 0.3%CVE-2026-5473LOWNASA cFS Pickle pickle.load deserializationEPSS 0.2%CVE-2026-5475MEDIUMNASA cFS CCSDS Header Size cfe_sb_priv.c CFE_SB_TransmitMsg memory corruptionEPSS 0.2%CVE-2026-22027MEDIUMCryptoLib Vulnerable to Heap Buffer Overflow in MariaDB SA Hexstring ConversionEPSS 0.2%CVE-2026-5476LOWNASA cFS cfe_tbl_passthru_codec.c CFE_TBL_ValidateCodecLoadSize integer overflowEPSS 0.2%CVE-2018-25367MEDIUMNASA openVSP 3.16.1 Denial of Service via Buffer OverflowEPSS 0.2%CVE-2026-72577CRITICALNASA fprime-gds - Missing Authentication and Path Traversal Enable Unauthenticated RCE and Spacecraft Command InjectionEPSS CVE-2026-72579HIGHNASA HyperCP - OS Command Injection via Malicious HTTP Response from Data ServerEPSS