Vulnerabilities (CVE)

Filtered by vendor Micropython Subscribe
Filtered by product Micropython
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-7158 1 Micropython 1 Micropython 2024-04-11 7.5 HIGH 9.8 CRITICAL
A vulnerability was found in MicroPython up to 1.21.0. It has been classified as critical. Affected is the function slice_indices of the file objslice.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.22.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-249180.
CVE-2023-7152 1 Micropython 1 Micropython 2024-04-11 5.2 MEDIUM 9.8 CRITICAL
A vulnerability, which was classified as critical, has been found in MicroPython 1.21.0/1.22.0-preview. Affected by this issue is the function poll_set_add_fd of the file extmod/modselect.c. The manipulation leads to use after free. The exploit has been disclosed to the public and may be used. The patch is identified as 8b24aa36ba978eafc6114b6798b47b7bfecdca26. It is recommended to apply a patch to fix this issue. VDB-249158 is the identifier assigned to this vulnerability.