CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

weston-embedded

uc-http

7 known vulnerabilities · sorted by CVSS score

CVE-2023-45318
CRITICAL10.0

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

silabs / gecko_software_development_kit+1
Network
Published Feb 20, 2024
CVE-2023-28391
CRITICAL9.0

A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

silabs / gecko_software_development_kit+2
Network
Published Nov 14, 2023
CVE-2023-25181
CRITICAL9.0

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

silabs / gecko_software_development_kit+2
Network
Published Nov 14, 2023
CVE-2023-28379
CRITICAL9.0

A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

silabs / gecko_software_development_kit+2
Network
Published Nov 14, 2023
CVE-2023-27882
CRITICAL9.0

A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

silabs / gecko_software_development_kit+2
Network
Published Nov 14, 2023
CVE-2023-31247
CRITICAL9.0

A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

silabs / gecko_software_development_kit+2
Network
Published Nov 14, 2023
CVE-2023-24585
HIGH7.7

An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.

silabs / gecko_software_development_kit+2
Network
Published Nov 14, 2023