<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Ember</title>
  <link>https://cvedaily.com/pages/tags/emberjs.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/emberjs.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Ember</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:05 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2025-1394 – The Ember ZNet stack’s packet buffer manager may read out of bound memory leadin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1394</guid>
    <pubDate>Wed, 30 Jul 2025 08:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-1394</strong></p>
  <p>The Ember ZNet stack’s packet buffer manager may read out of bound memory leading to an assert, causing a Denial of Service (DoS).</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-252</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6351 – A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6351</guid>
    <pubDate>Tue, 28 Jan 2025 14:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6351</strong></p>
  <p>A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6352 – A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6352</guid>
    <pubDate>Mon, 13 Jan 2025 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6352</strong></p>
  <p>A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-51394 – High traffic environments may result in NULL Pointer Dereference vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51394</guid>
    <pubDate>Fri, 23 Feb 2024 20:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-51394</strong></p>
  <p>High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-51393 – Due to an allocation of resources without limits, an uncontrolled resource consu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51393</guid>
    <pubDate>Fri, 23 Feb 2024 20:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-51393</strong></p>
  <p>Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko SDK v4.4.0) which may enable attackers to trigger a bus fault and crash of the device, requiring a reboot in order to rejoin the network.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-51392 – Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51392</guid>
    <pubDate>Fri, 23 Feb 2024 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-51392</strong></p>
  <p>Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel attacks.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-1240</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6874 – Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6874</guid>
    <pubDate>Mon, 05 Feb 2024 18:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6874</strong></p>
  <p>Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-41096 – Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41096</guid>
    <pubDate>Thu, 26 Oct 2023 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-41096</strong></p>
  <p>Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules)  allows potential modification or extraction of network credentials stored in flash.   This issue affects Silicon Labs Ember ZNet SDK: 7.3.1 and earlier.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41094 – TouchLink packets processed after timeout or out of range due to Operation on a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41094</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41094</guid>
    <pubDate>Wed, 04 Oct 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41094</strong></p>
  <p>TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration  This issue affects Ember ZNet 7.1.x from 7.1.3 through 7.1.5; 7.2.x from 7.2.0 through 7.2.3; Version 7.3 and later are unaffected</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41094">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24939 – A malformed packet containing an invalid destination address, causes a stack ove...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24939</guid>
    <pubDate>Fri, 18 Nov 2022 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24939</strong></p>
  <p>A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24938 – A malformed packet causes a stack overflow in the Ember ZNet stack. This causes ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24938</guid>
    <pubDate>Mon, 14 Nov 2022 18:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24938</strong></p>
  <p>A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24937 – Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24937</guid>
    <pubDate>Mon, 14 Nov 2022 18:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24937</strong></p>
  <p>Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4170 – In general, Ember.js escapes or strips any user-supplied content before insertin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4170</guid>
    <pubDate>Thu, 30 Jun 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4170</strong></p>
  <p>In general, Ember.js escapes or strips any user-supplied content before inserting it in strings that will be sent to innerHTML. However, the `tagName` property of an `Ember.View` was inserted into such a string without being sanitized. This means that if an application assigns a view's `tagName` to user-supplied data, a specially-crafted payload could execute arbitrary JavaScript in the context o…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0014 – Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0014</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0014</guid>
    <pubDate>Thu, 15 Feb 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0014</strong></p>
  <p>Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application using the "{{group}}" Helper and a crafted payload.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0014">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0013 – Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0013</guid>
    <pubDate>Thu, 15 Feb 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0013</strong></p>
  <p>Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application that contains templates whose context is set to a user-supplied primitive value and also contain the `{{this}}` special Handlebars variable.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-1866 – Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-1866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-1866</guid>
    <pubDate>Wed, 20 Sep 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-1866</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-1866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-7565 – Cross-site scripting (XSS) vulnerability in Ember.js 1.8.x through 1.10.x, 1.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7565</guid>
    <pubDate>Thu, 13 Apr 2017 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-7565</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Ember.js 1.8.x through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before 1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2, and 2.2.x before 2.2.1 allows remote attackers to inject arbitrary web script or HTML.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2014-0046 – Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0046</guid>
    <pubDate>Thu, 27 Feb 2014 15:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2014-0046</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1.4.x before 1.4.0-beta.6, when used in non-block form, allows remote attackers to inject arbitrary web script or HTML via the title attribute.</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-3355 – Ember 0.5.7 places a zero-length directory name in the LD_LIBRARY_PATH, which al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-3355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-3355</guid>
    <pubDate>Wed, 20 Oct 2010 18:00:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-3355</strong></p>
  <p>Ember 0.5.7 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-3355">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
