moos-ivp
15 known vulnerabilities in moos-ivp, 6 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-85456 CVSS 6.8 medium MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to…
- CVE-2026-85449 CVSS 8.7 high MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers…
- CVE-2026-85448 CVSS 8.7 high MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within…
- CVE-2026-85447 CVSS 8.7 high MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits…
- CVE-2026-85446 CVSS 8.7 high MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a…
- CVE-2026-85445 CVSS 8.7 high MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count…
- CVE-2026-85444 CVSS 8.7 high MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip…
- CVE-2026-85439 CVSS 8.5 high MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that…
- CVE-2026-85438 CVSS 9.3 critical MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from…
- CVE-2026-85437 CVSS 9.3 critical MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled…
- CVE-2026-85435 CVSS 9.3 critical MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher…
- CVE-2026-85434 CVSS 9.3 critical MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can…
- CVE-2026-85429 CVSS 8.7 high MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection…
- CVE-2026-85426 CVSS 9.3 critical MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can…
- CVE-2026-85425 CVSS 9.3 critical MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text…