VYPR

Vendor CVEs

Nasa

All CVEs

81 total · sorted by risk
  • CVE-2026-72577CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies…

  • CVE-2025-25373CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.00

    The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.

  • CVE-2024-55030CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands.

  • CVE-2024-55028CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file.

  • CVE-2025-29913CriMar 17, 2025
    risk 0.64cvss 9.8epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A critical heap buffer overflow vulnerability…

  • CVE-2025-29911CriMar 17, 2025
    risk 0.64cvss 9.8epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A critical heap buffer overflow vulnerability…

  • CVE-2024-35056CriMay 21, 2024
    risk 0.64cvss 9.8epss 0.01

    NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.

  • CVE-2026-67979CriAug 4, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.

  • CVE-2018-3849HigApr 16, 2018
    risk 0.58cvss 8.8epss 0.04

    In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

  • CVE-2018-3848HigApr 16, 2018
    risk 0.58cvss 8.8epss 0.04

    In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

  • CVE-2025-64096HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.00

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to 1.4.2, there is a missing bounds check…

  • CVE-2018-3847HigAug 1, 2018
    risk 0.57cvss 8.8epss 0.03

    Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted images parsed via the library, can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT…

  • CVE-2018-3846HigApr 16, 2018
    risk 0.57cvss 8.8epss 0.03

    In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

  • CVE-2018-1000048HigFeb 9, 2018
    risk 0.57cvss 8.8epss 0.02

    NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in remote code execution. This attack appear to be exploitable via Victim tries to retrieve and process a weather data file.

  • CVE-2018-1000047HigFeb 9, 2018
    risk 0.57cvss 8.8epss 0.02

    NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execution. This attack appear to be exploitable via Victim opens an untrusted file for optimization using Kodiak library.

  • CVE-2026-21898HigJan 10, 2026
    risk 0.53cvss 8.2epss 0.00

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the…

  • CVE-2024-54130CriDec 5, 2024
    risk 0.53cvss epss 0.00

    The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A segmentation fault occurs with ION-DTN BPv7 software version 4.1.3 when a bundle with a Destination Endpoint ID (EID) set to dtn:none is received. This causes…

  • CVE-2024-54129CriDec 5, 2024
    risk 0.53cvss epss 0.00

    The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version ION-DTN BPv7 implementation version 4.1.3 when receiving a bundle with an improper reference to the imc scheme with valid…

  • CVE-2026-72579HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.01

    An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept or spoof responses from oceandata.sci.gsfc.nasa.gov to execute arbitrary system commands on the researcher's workstation.

  • CVE-2026-67977HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-67975HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.

  • CVE-2026-67974HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.

  • CVE-2026-67973HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

  • CVE-2026-67970HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.

  • CVE-2026-67969HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.

  • CVE-2026-67976HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters.

  • CVE-2026-67972HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure.

  • CVE-2026-22697HigJan 10, 2026
    risk 0.49cvss 7.5epss 0.00

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, CryptoLib’s KMC crypto…

  • CVE-2025-61910HigOct 7, 2025
    risk 0.49cvss 7.5epss 0.00

    The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A BPv7 bundle with a malformed extension block causes uncontrolled memory allocation inside ION-DTN 4.1.3s, leading to receiver thread termination and a…

  • CVE-2025-25374HigMar 25, 2025
    risk 0.49cvss 7.5epss 0.01

    In NASA cFS (Core Flight System) Aquila, it is possible to put the onboard software in a state that will prevent the launch of any external application, causing a platform denial of service.

  • CVE-2025-25372HigMar 25, 2025
    risk 0.49cvss 7.5epss 0.00

    NASA cFS (Core Flight System) Aquila is vulnerable to segmentation fault via sending a malicious telecommand to the Memory Management Module.

  • CVE-2025-25371HigMar 25, 2025
    risk 0.49cvss 7.5epss 0.01

    NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system.

  • CVE-2025-29910HigMar 17, 2025
    risk 0.49cvss 7.5epss 0.00

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A memory leak vulnerability was identified in…

  • CVE-2024-44912HigSep 27, 2024
    risk 0.49cvss 7.5epss 0.00

    NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c).

  • CVE-2024-44911HigSep 27, 2024
    risk 0.49cvss 7.5epss 0.01

    NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c).

  • CVE-2024-44910HigSep 27, 2024
    risk 0.49cvss 7.5epss 0.01

    NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).

  • CVE-2024-35060HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in the YAML Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands via supplying a crafted YAML file.

  • CVE-2024-35059HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.

  • CVE-2024-35058HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in the API wait function of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via supplying a crafted string.

  • CVE-2024-35057HigMay 21, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.

  • CVE-2026-21897HigJan 10, 2026
    risk 0.47cvss 7.3epss 0.00

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the…

  • CVE-2024-35061HigMay 21, 2024
    risk 0.47cvss 7.3epss 0.01

    NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, fully remote code execution.

  • CVE-2026-18064HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.00

    An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause…

  • CVE-2026-15352HigJul 16, 2026
    risk 0.42cvss 7.5epss 0.00

    A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.

  • CVE-2023-45282HigOct 6, 2023
    risk 0.42cvss 7.5epss 0.01

    In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.

  • CVE-2018-25367MedMay 25, 2026
    risk 0.40cvss 6.2epss 0.00

    NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input…

  • CVE-2024-55029MedMar 25, 2025
    risk 0.40cvss 6.1epss 0.00

    NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.

  • CVE-2023-45884MedNov 9, 2023
    risk 0.35cvss 6.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.

  • CVE-2026-5474MedApr 3, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must…

  • CVE-2026-21899MedJan 10, 2026
    risk 0.31cvss 4.7epss 0.00

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, in base64urlDecode,…

Page 1 of 2