VYPR

Vendor CVEs

Nasa

All CVEs

89 total · sorted by risk
  • CVE-2026-15352HigJul 16, 2026
    risk 0.42cvss 7.5epss 0.01

    A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.

  • CVE-2023-45282HigOct 6, 2023
    risk 0.42cvss 7.5epss 0.01

    In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.

  • CVE-2026-82479MedAug 30, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from…

  • CVE-2018-25367MedMay 25, 2026
    risk 0.40cvss 6.2epss 0.00

    NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can trigger a denial of service by pasting a 5000-byte payload into the name input…

  • CVE-2024-55029MedMar 25, 2025
    risk 0.40cvss 6.1epss 0.00

    NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.

  • CVE-2023-45884MedNov 9, 2023
    risk 0.35cvss 6.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.

  • CVE-2026-82802MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw has been found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSearch/handler.js of the component granules Endpoint. Executing a manipulation of the argument openSearchOsdd…

  • CVE-2026-5474MedApr 3, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Performing a manipulation results in heap-based buffer overflow. The attacker must…

  • CVE-2026-21899MedJan 10, 2026
    risk 0.31cvss 4.7epss 0.00

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, in base64urlDecode,…

  • CVE-2026-5475MedApr 3, 2026
    risk 0.29cvss 5.5epss 0.00

    A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler. Executing a manipulation can lead to memory corruption. The project was informed of the problem early…

  • CVE-2023-45885MedNov 9, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross Site Scripting (XSS) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to run arbitrary code via the new component feature in the flexibleLayout plugin.

  • CVE-2026-5476MedApr 3, 2026
    risk 0.23cvss 4.6epss 0.00

    A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize of the file cfe/modules/tbl/fsw/src/cfe_tbl_passthru_codec.c. The manipulation leads to integer overflow. The complexity of an attack is rather high. The…

  • CVE-2026-5473MedApr 3, 2026
    risk 0.22cvss 4.5epss 0.00

    A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The…

  • CVE-2019-1010060CriJul 16, 2019
    risk 0.01cvss 9.8epss 0.06

    NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: over 40 source code files were changed. The attack vector is: remote unauthenticated attacker. The fixed version is: 3.43. NOTE: this CVE refers to the issues…

  • CVE-2026-41144NonApr 22, 2026
    risk 0.00cvss 0.0epss 0.00

    F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize uses U32 addition that wraps around on overflow. An attacker-crafted DataPacket…

  • CVE-2026-22027MedJan 10, 2026
    risk 0.00cvss 6.0epss 0.00

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the…

  • CVE-2026-22026HigJan 10, 2026
    risk 0.00cvss 7.5epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the libcurl…

  • CVE-2026-22025LowJan 10, 2026
    risk 0.00cvss 3.7epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, when the KMC server…

  • CVE-2026-22024MedJan 10, 2026
    risk 0.00cvss 5.3epss 0.00

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, the…

  • CVE-2026-22023HigJan 10, 2026
    risk 0.00cvss 7.5epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, there is an…

  • CVE-2026-21900MedJan 10, 2026
    risk 0.00cvss 5.9epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, an out-of-bounds heap…

  • CVE-2025-59534HigSep 23, 2025
    risk 0.00cvss 7.3epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.2, there is a command…

  • CVE-2025-54878HigAug 11, 2025
    risk 0.00cvss 8.6epss 0.00

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A heap buffer overflow vulnerability exists in…

  • CVE-2025-46675LowApr 27, 2025
    risk 0.00cvss 3.5epss 0.00

    In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.

  • CVE-2025-46674LowApr 27, 2025
    risk 0.00cvss 3.5epss 0.01

    NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle.

  • CVE-2025-46673MedApr 27, 2025
    risk 0.00cvss 4.9epss 0.00

    NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security protocol (SDLS).

  • CVE-2025-46672LowApr 27, 2025
    risk 0.00cvss 3.5epss 0.01

    NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking.

  • CVE-2025-30356CriApr 1, 2025
    risk 0.00cvss 9.8epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In 1.3.3 and earlier, a heap buffer overflow…

  • CVE-2025-30216CriMar 25, 2025
    risk 0.00cvss 9.4epss 0.03

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, a Heap Overflow…

  • CVE-2025-29912CriMar 17, 2025
    risk 0.00cvss 9.8epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, an unsigned integer…

  • CVE-2025-29909CriMar 17, 2025
    risk 0.00cvss 9.8epss 0.01

    CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. In versions 1.3.3 and prior, a heap buffer…

  • CVE-2022-23054MedFeb 20, 2022
    risk 0.00cvss 6.1epss 0.01

    Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

  • CVE-2022-23053MedFeb 20, 2022
    risk 0.00cvss 6.1epss 0.01

    Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later…

  • CVE-2022-22126MedFeb 20, 2022
    risk 0.00cvss 6.1epss 0.01

    Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection of malicious JavaScript into the ‘URL’ field. This issue affects: nasa openmct 1.7.7 version and prior versions; 1.3.0 version and later versions.

  • CVE-2018-1000046HigFeb 9, 2018
    risk 0.00cvss 7.8epss 0.02

    NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remote code execution. This attack appear to be exploitable via Victim opening a specially crafted radar data file. This vulnerability appears to have been fixed in…

  • CVE-2018-1000045HigFeb 9, 2018
    risk 0.00cvss 7.8epss 0.02

    NASA Singledop version v1.0 contains a CWE-502 vulnerability in NASA Singledop library (Weather data) that can result in remote code execution. This attack appear to be exploitable via Victim opening a specially crafted radar data file. This vulnerability appears to have been…

  • CVE-2014-7113Oct 19, 2014
    risk 0.00cvss —epss 0.00

    The NASA Universe Wallpapers Xeus (aka com.xeusNASA) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2009-2850Aug 18, 2009
    risk 0.00cvss —epss 0.03

    Multiple buffer overflows in NASA Common Data Format (CDF) allow context-dependent attackers to execute arbitrary code, as demonstrated using (1) an array index error in the ReadAEDRList64 function, and other errors in the (2) SearchForRecord_r_64, (3) LastRecord64, (4)…

  • CVE-2008-2080May 6, 2008
    risk 0.00cvss —epss 0.04

    Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags.

Page 2 of 2