themoos core-moos

12 known vulnerabilities in themoos core-moos, 3 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-85455 CVSS 8.8 high MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds…
  • CVE-2026-85454 CVSS 5.2 medium MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one…
  • CVE-2026-85453 CVSS 5.3 medium MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious…
  • CVE-2026-85451 CVSS 7.1 high MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded…
  • CVE-2026-85450 CVSS 8.7 high MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and…
  • CVE-2026-85443 CVSS 8.7 high MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs…
  • CVE-2026-85442 CVSS 8.7 high MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated…
  • CVE-2026-85441 CVSS 8.7 high MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated…
  • CVE-2026-85440 CVSS 9.3 critical MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote…
  • CVE-2026-85432 CVSS 8.8 high MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to…
  • CVE-2026-85428 CVSS 9.3 critical MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows…
  • CVE-2026-85424 CVSS 9.3 critical MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish…