PX4 Autopilot
Flight control software for drones and other unmanned vehicles.
Vulnerabilities affecting this build
To upgrade
cyclonedds 314887ca403c2fb0a0316add22672102936ed36c Listed for this exact version. Open the CVEs to find the fix.5 vulnerabilities · an NVD scanner reports 2
- CVE-2024-10838 cyclonedds missed by NVD scannershigh
Integer Underflow in DDS_Security_Deserialize_ methods may lead to OOB read
- CVE-2021-38441 medium
Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker t
- CVE-2021-38443 medium
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write ar
- OSV-2023-273 OSV
Heap-buffer-overflow in add_complete_typeobj
- OSV-2023-556 OSV
Heap-buffer-overflow in xt_valid_enum_values
To look at
libtomcrypt 673f5ce29015a9bba3c96792920a10601b5b0718 A vendor fork: check whether it carries the fixes4 vulnerabilities · an NVD scanner reports 4
- CVE-2019-17362 critical
In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detec
- CVE-2016-6129 high
The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate t
- CVE-2005-1600 high
A "mathematical flaw" in the implementation of the El Gamal signature algorithm for LibTomCrypt 1.0 to 1.0.2 allows atta
- CVE-2018-12437 medium
LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden N
No advisory source
- dsdl 993be80a62ec957c01fb41115b83663959a49f46
- fuzztest 1e47f9d7437de5c3ee4cb0ac860d5ec875478059
- heatshrink 052e6de72f67f1777198bce98f3de62f7f3c16a0
- iq-module-communication-cpp c488af4e8807de80739aa48efd2ea51614dd8195
- jmavsim 66b764ada522893c05224950aa6268c809f8e48a
- libevents 9ef591c447fe0386d698bf6fb9a6d27e43988ee4
- libtommath fd73d7630b9d3ed5a79d613ff680a549e9780de7
- lord-microstrain-mip-sdk 35596994b60ba89fe02f71ce5127baa5e7ff2bbf
- mavlink 1.0.12..
- micro-xrce-dds-client 711aef423edd1820347b866d1e4164832df35d04
- monocypher baca5d31259c598540e4d1284bc8d8f793abf83a
- public-regulated-data-types d0bd6516dac8ff61287fe49a9f2c75e7d4dc1b8e
- px4-flightgear-bridge f47ce7b5fbbb3aa43d33d2be1f6cd3746b13d5bf
- px4-gazebo-models b6127f4ec20de867e215fb5f78ae88b80f371909
- px4-gpsdrivers 0b9695881bd1e8f830ab4538ab3acc0050019eba
- px4-jsbsim-bridge f37ec259bd7a43565fe0ff4722465b7a303200f6
- px4-sitl-gazebo-classic 6697ab169ceab512dc706acea63df4c882662c60
- pydronecan 1.0.16..1.0.17
- rosidl bf5682e4747843d1d5133b9a2b54ce6f12f166c7
- sbgecom 80b121c7714083cc4868c0fdb8c41623c7ef9c93
- tflite-micro 3c0b1e3091e4ea423e1bf9da89d41d09517eb0c9
- zenoh-pico 6ec4dc1995f185330e4f6faa8c719eb86f180deb
How this was made, and what it is not
We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.
It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.