Windriver

    Dashboard / Vendors

    Products: 5
    Vulnerabilities: 50
    Known Exploited: 0
    15
    Critical Level Threats
    21
    High Level Threats
    14
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-26503

    Buffer manipulation

    Last Modified: Apr 15, 2026
    Published: Sep 18, 2025

    CVE-2025-26499

    Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This flaw allows one user to be granted a token intended for another user, resulting in impersonation until the session is ended. This flaw cannot be intentionally exploited due to the required concurring action by two users. However, if the event occurs a user would be inadvertently exposed to another user’s system rights and data access.

    Last Modified: Apr 15, 2026
    Published: Sep 11, 2025

    CVE-2023-51787

    An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task memory is not freed, resulting in a memory leak.

    Last Modified: Jan 13, 2026
    Published: Feb 15, 2024

    CVE-2023-38346

    An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from absolute paths or stop processing when encountering relative paths that are outside of the extraction path, unless otherwise forced. This could lead to unexpected and undocumented behavior, which in general could result in a directory traversal, and associated unexpected behavior.

    Last Modified: Nov 21, 2024
    Published: Sep 22, 2023

    CVE-2022-38767

    An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access procedure.

    Last Modified: Apr 14, 2026
    Published: Nov 25, 2022
    Items Per Page
    Windriver Vulnerabilities & Security CVEs | CVE-DB