CVE-2014-125106
Published Jun 17, 2023Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string.
Vendor archive
4 CVEs tagged to vendor nanopb_project — 1 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.
Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string.
Nanopb is a small code-size Protocol Buffers implementation in ansi C. In Nanopb before versions 0.3.9.8 and 0.4.5, decoding a specifically formed message can cause invalid `free(…
Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can leak memory if dynamic allocatio…
There is a potentially exploitable out of memory condition In Nanopb before 0.4.1, 0.3.9.5, and 0.2.9.4. When nanopb is compiled with PB_ENABLE_MALLOC, the message to be decoded c…