VYPR

picoTCP-NG

by virtualsquare

CVEs (5)

  • CVE-2021-33304CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitrary code.

  • CVE-2023-35849HigJun 19, 2023
    risk 0.00cvss 7.5epss 0.01

    VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not properly check whether header sizes would result in accessing data outside of a packet.

  • CVE-2023-35848HigJun 19, 2023
    risk 0.00cvss 7.5epss 0.01

    VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 lacks certain size calculations before attempting to set a value of an mss structure member.

  • CVE-2023-35847HigJun 19, 2023
    risk 0.00cvss 7.5epss 0.01

    VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not have an MSS lower bound (e.g., it could be zero).

  • CVE-2023-35846HigJun 19, 2023
    risk 0.00cvss 7.5epss 0.01

    VirtualSquare picoTCP (aka PicoTCP-NG) through 2.1 does not check the transport layer length in a frame before performing port filtering.