Vulnerabilities (CVE)

Filtered by vendor Cypress
Filtered by product Cyw20819a1
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13916 1 Cypress 3 Cyw20735b1, Cyw20819a1, Wiced Studio 2024-11-21 5.8 MEDIUM 8.8 HIGH
An issue was discovered in Cypress (formerly Broadcom) WICED Studio 6.2 CYW20735B1 and CYW20819A1. As a Bluetooth Low Energy (BLE) packet is received, it is copied into a Heap (ThreadX Block) buffer. The buffer allocated in dhmulp_getRxBuffer is four bytes too small to hold the maximum of 255 bytes plus headers. It is possible to corrupt a pointer in the linked list holding the free buffers of the g_mm_BLEDeviceToHostPool Block pool. This pointer can be fully controlled by overflowing with 3 byt ...

Show More