Incomplete in the CWE catalog · 3 CVEs mapped
Casting a non-structure type to a structure type and accessing a field can lead to memory access errors or data corruption.
⚡ A sneaky type confusion vulnerability lurks in iccDEV versions prior to 2.3.1.2, possibly letting attackers cause some serious color chaos! 🎨 Think of this vulnerability like a faulty color printer that misinterprets the ink settings, producing colors that aren't just wrong but could cause a whole batch of prints to turn out unusable. It's like ordering a vibrant red, only to receive a muddy brown — not exactly what you wanted! An attacker could exploit this vulnerability to manipulate ICC color profiles, leading to unexpected behavior in applications that rely on accurate color management. This might cause visual disruptions in critical systems, affecting everything from graphic design to manufacturing processes where color precision is paramount.
Zephyr JSON decoder incorrectly decodes array of array. Zephyr versions >= >1.14.0, >= >2.5.0 contain Attempt to Access Child of a Non-structure Pointer (CWE-588). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-289f-7mw3-2qf4
DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses. Zephyr versions >= > v2.4.0 contain NULL Pointer Dereference (CWE-476), Attempt to Access Child of a Non-structure Pointer (CWE-588). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-94jg-2p6q-5364