Exposure monitor

Vulnerabilities

Automotive Vulnerabilities. Hunted worldwide every 24 hours, across 🇺🇸🇨🇳🇯🇵🇰🇷🇹🇼🇩🇪🇫🇷🇨🇭🇦🇹🇳🇱🇧🇪🇵🇱🇨🇦🇱🇺🇪🇺. Stay ahead.

1962advisories found
Clear filters
Results
nvdmedium · 5.4

cve-2026-18393

FFmpeg contains a heap buffer overflow vulnerability in its tdsc_load_cursor() function, triggered by crafted TDSC cursor data in a video file. A remote attacker could exploit this to cause a denial of service or potentially execute arbitrary code. The advisory lists affected products as Red Hat Enterprise Linux AI and Red Hat OpenShift AI, but does not confirm automotive deployment; this could be relevant where FFmpeg is deployed in automotive systems, and the severity is not explicitly stated in the advisory. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.4

cve-2026-13481

The advisory describes an out-of-bounds read vulnerability in Zephyr's IEEE 1588 PTP management-message parser, specifically in the handling of the PTP_MGMT_TIME management ID. An attacker on the local PTP segment could send a short management TLV, causing the parser to read and write 8 bytes beyond the validated data, leading to minor information exposure and corruption of the parsed timestamp value. The severity is limited, with no crash or memory corruption beyond the same object. This could be relevant where Zephyr's PTP stack is deployed in automotive systems, such as in time-synchronized in-vehicle networks. Confirm applicability through the product SBOM or dependency inventory.

nvdmedium · 5.3

cve-2026-57497

webtransport-go before version 0.11.1 contains a flaw where an unknown WebTransport capsule on the HTTP/3 request stream is read entirely into memory, allowing a malicious peer to send a large capsule and exhaust memory, potentially disrupting or crashing the affected process. This could be relevant where webtransport-go is deployed in automotive systems, for example in vehicle telematics or embedded connectivity services. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.3

cve-2026-15892

A heap memory leak exists in Zephyr's mcumgr settings-management handlers when the heap buffer type and access hook are both enabled and the hook rejects a request with MGMT_CB_ERROR_RC, causing allocated memory to be freed only at reboot. An attacker able to send settings read, write, or delete commands over the unauthenticated SMP transport (Bluetooth LE, UART, or UDP depending on configuration) can repeatedly trigger rejected requests, steadily exhausting the kernel heap until allocation fails and mcumgr service is denied, with availability-only impact and no memory corruption or information disclosure. This could be relevant where Zephyr with mcumgr is deployed in automotive or embedded systems; confirm applicability through the product SBOM or dependency inventory.

nvdmedium · 5.3

cve-2026-15461

A type-confusion flaw in Zephyr's HL78xx GNSS NMEA driver causes parsed satellite data to be written through an uninitialized pointer, which most likely crashes the system (denial of service) and could corrupt adjacent memory on MMU-less targets. The affected component is the HL78xx modem GNSS driver, which is enabled by default on devices using that GNSS source, and an attacker able to influence the GNSS radio signal could trigger the faulty write; confidentiality is not affected and exploitation requires the satellites feature to be active, making attack complexity high. This could be relevant where the Zephyr HL78xx GNSS driver is deployed in automotive systems. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.3

cve-2026-86469

GLib2 contains a time-of-check-to-time-of-use symlink race in its file replacement fallback path. A local attacker who can write to the destination directory could exploit this to redirect a file write to another file, potentially corrupting or overwriting data. The flaw affects Red Hat Enterprise Linux and related products, with severity not explicitly stated in the advisory. This could be relevant where GLib2 is deployed in automotive systems, such as in embedded Linux environments. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.3

cve-2026-20504

The advisory describes a vulnerability in a MediaTek modem component where a missing bounds check could allow a remote denial of service, causing a system crash if a user equipment (UE) connects to a rogue base station controlled by an attacker. No user interaction or additional execution privileges are needed for exploitation. This could be relevant where MediaTek chipsets are deployed in automotive systems, such as for cellular connectivity; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.3

cve-2026-20503

The advisory describes a vulnerability in a MediaTek modem component where a missing bounds check could allow a remote denial of service, causing a system crash if a user equipment connects to a rogue base station controlled by an attacker. No user interaction or additional privileges are required for exploitation. This could be relevant where MediaTek chipsets are deployed in automotive systems, such as in-vehicle telematics or infotainment modems; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.3

cve-2026-82618

Systerel S2OPC versions up to 1.7.3 contain a vulnerability in the String Array Range Writing component, specifically in the function set_range_matrix_on_string_array, which can cause an out-of-bounds read. This flaw can be exploited remotely, potentially allowing an attacker to access unintended memory data. The severity is not explicitly stated in the advisory, and the vendor has not yet responded to the issue report. This could be relevant where S2OPC is deployed in automotive systems, such as in industrial or embedded communication stacks, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.3

cve-2026-82552

Linux Foundation Magma version 1.9.0 contains a denial-of-service vulnerability in the gNB Termination Handler component, specifically in the file tasks/ngap/ngap_amf.c. An attacker can exploit this remotely to disrupt service, and the exploit has been publicly disclosed. This could be relevant where Magma is deployed in automotive or road-transport systems, but the advisory does not confirm such use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.3

cve-2026-77680

This advisory describes a denial-of-service vulnerability in libsoup, a software library used for handling HTTP communications. An attacker can send a specially crafted HTTP request with many repeated data ranges, causing the server to consume excessive CPU time and temporarily block its ability to process other requests, though no data is corrupted or stolen. The issue affects libsoup versions that include a prior fix for CVE-2025-32907 but not the latest correction, and the severity is a CPU exhaustion availability problem. This could be relevant where libsoup is deployed in automotive systems, such as in infotainment or telematics units that run HTTP servers. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.3

cve-2026-13213

The advisory describes a denial-of-service vulnerability in the Zephyr Bluetooth Hearing Access Service (HAS) GATT server, where a previously bonded peer can trigger a crash by reconnecting before the service is registered. An attacker exploiting this can cause a remotely triggerable crash via Bluetooth, resulting in service outage, with no memory corruption or information disclosure. This could be relevant where Zephyr's Bluetooth stack is deployed in automotive systems, such as for in-vehicle audio or connectivity features; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.3

cve-2026-13343

The advisory describes a vulnerability in the Zephyr project's MIDI 2.0 UMP Stream responder library, where reply packets are built with uninitialised stack memory, causing 8 bytes of stale data to be disclosed to a remote peer. An attacker can trigger this repeatedly via UDP datagrams in the Network MIDI 2.0 server or through USB MIDI 2.0 hosts, leading to a confidentiality-only information leak with no memory corruption, integrity, or availability impact. This could be relevant where the MIDI 2.0 library is deployed in automotive systems, such as in-vehicle infotainment or telematics, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

csaf_murrelektronikgmbhmedium · 5.3

vde-2026-061

An information disclosure vulnerability in Murrelektronik Xelity switches, which are industrial network devices, causes MAC addresses from the device's table to be written into a web-accessible log when an administrator uses the 'Copy learned MAC Addresses' function. An unauthenticated attacker with network access to the web interface can retrieve these MAC addresses, which could aid in network reconnaissance and MAC spoofing attacks against port-security or 802.1X mechanisms. The issue was introduced in version 2.1.0 and is fixed in firmware version 2.1.1, with the severity reflecting a loss of confidentiality.

cvelistv5medium · 5.3

cve-2026-12999

The advisory describes a vulnerability in the Infineon Airoc Wi-Fi driver where failed packet transmissions permanently leak buffers from a small, fixed pool, eventually exhausting it and causing a permanent loss of Wi-Fi connectivity until the device is rebooted. An attacker with Wi-Fi proximity could trigger these failures, leading to a denial-of-service condition, though the attack is complex to execute reliably and only affects availability. This could be relevant where the Infineon Airoc Wi-Fi driver is deployed in automotive systems, such as in-vehicle infotainment or telematics units, but the advisory does not confirm automotive use; confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.3

cve-2026-76919

The advisory describes a denial-of-service vulnerability in Wireshark, specifically a crash in the ESS protocol dissector affecting versions 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18. An attacker could exploit this by sending crafted network traffic to cause the application to crash, disrupting analysis. This could be relevant where Wireshark is deployed in automotive systems for network diagnostics or security testing, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 5.3

cve-2026-12634

The advisory describes an out-of-bounds stack write vulnerability in the Zephyr settings subsystem's NVS backend, where a malformed stored setting name can cause a single NUL byte to be written past a fixed-size stack buffer. An attacker with flash access to the settings partition could trigger a crash or denial of service, though the impact is limited to stack corruption without reliable code execution or confidentiality loss. This could be relevant where Zephyr is deployed in automotive systems, such as embedded controllers or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

fkie_nvdmedium · 5.3

cve-2026-54909

This vulnerability affects the STUN protocol implementation used in automotive systems for WebRTC-based infotainment, remote diagnostics, and vehicle-to-cloud communication, where malformed network packets can trigger a panic in the XORMappedAddress parsing logic. An attacker on the same network or via a compromised server could send a specially crafted STUN or ICE Binding-response to crash the affected service, causing a denial of service that disrupts connectivity features. The severity is moderate, as it requires network access and only impacts availability, not data integrity or vehicle control, but it is fixed in version 3.1.3 and should be patched promptly.

fkie_nvdmedium · 5.3

cve-2026-24227

This vulnerability affects NVIDIA TensorRT, which is an inference optimization engine used in automotive AI systems for ADAS, autonomous driving perception, and in-cabin monitoring. An attacker could exploit this by sending a maliciously crafted model file, leading to code execution on the affected system. This is a critical risk that could allow an attacker to take control of safety-critical vehicle functions.

csaf_nozominetworksmedium · 5.2

nn-2026:14-01

This vulnerability affects the Windows-based diagnostic and monitoring tools used in automotive engineering labs and dealership service centers, where the Npcap driver is installed as part of the Arc software suite. Because the driver was left accessible to all local users instead of being restricted to administrators, any low-privileged user on the host machine could potentially intercept or manipulate network traffic, including data from vehicle diagnostic sessions. The severity is medium, as exploitation requires local access to the host, but it could expose sensitive vehicle data or disrupt testing operations.

nvdmedium · 5.1

cve-2026-21066

This vulnerability affects the Bluetooth stack used in automotive hands-free calling, media streaming, and phone-as-a-key systems, as it resides in Samsung’s audio codec library for FLAC file decoding on mobile devices. A local attacker could exploit improper input validation to write out-of-bounds memory, potentially crashing the system or executing arbitrary code, though the attack requires local access and is rated as a moderate severity issue. Samsung has addressed this in its August 2026 security update, so vehicles relying on Samsung-based infotainment or companion apps should apply the patch to prevent memory corruption.

nvdmedium · 5.1

cve-2026-21067

This vulnerability affects the Bluetooth stack used in automotive hands-free calling, media streaming, and phone-as-a-key systems, as it resides in the libsmsd.so library found in Samsung mobile devices that often pair with vehicle infotainment systems. A local attacker with access to the device could exploit improper input validation to write out-of-bounds memory, potentially crashing the system or executing malicious code. The severity is high, as it could compromise the connected device and, by extension, any vehicle systems it interfaces with, though it requires local access to exploit.

cvelistv5medium · 5.0

cve-2026-12519

The advisory describes a vulnerability in the Zephyr WNC-M14A2A LTE-M modem driver, where an out-of-bounds stack read and write can occur when parsing unsolicited network events. An attacker, such as a rogue cellular base station, could trigger this flaw to cause a denial of service by crashing the modem RX thread, and potentially disclose stack memory into logs. This could be relevant where the WNC-M14A2A modem is deployed in automotive systems, and the severity is not explicitly rated but involves stack corruption and information disclosure. Confirm applicability through the product SBOM or dependency inventory.

cvelistv5medium · 4.9

cve-2026-18374

The advisory describes a heap buffer overflow vulnerability in the GNU C Library (glibc) version 2.45 or earlier, triggered when an attacker-controlled mode string is passed to the fopen function with an empty ,ccs= syntax extension. An attacker could exploit this to cause memory corruption, potentially leading to a crash or arbitrary code execution, though the advisory notes this usage pattern is uncommon in standard GNU/Linux distributions. This could be relevant where glibc is deployed in automotive systems, such as in infotainment or telematics units, but the advisory does not confirm automotive use. Confirm applicability through the product SBOM or dependency inventory.

fkie_nvdmedium · 4.9

cve-2026-62947

OpenWrt is the Linux-based operating system used in many automotive-grade Wi-Fi routers and telematics gateways for in-vehicle connectivity and OTA update management. This vulnerability allows an attacker with limited access to read sensitive system files like password hashes by exploiting a path traversal flaw in the file download handler. The issue is rated critical and requires immediate patching to prevent unauthorized access to vehicle network infrastructure.