CVE-2025-1394
The Ember ZNet stack’s packet buffer manager may read out of bound memory leading to an assert, causing a Denial of Service (DoS).
All CVEs associated with "Ember". Page 1/1 • 19 CVEs.
A curated feed of “Ember”-related CVEs appears below. We currently track 19 CVEs for this tag (all time). In the last 365 days, 1 were published. Average CVSS is 5.9 (all time; 5.9 over 365d), and 11% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-252 - Unchecked Return Value.
In our taxonomy this topic maps to a LOW impact class. Language runtimes and libraries cascade through dependency graphs. Upgrade runtime and toolchain, pin versions, rebuild images, and enable SAST or DAST and linters. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.
| Cycle | Release | Latest | Premier Support | EOL | LTS |
|---|---|---|---|---|---|
| 6.11 | 6.11.1 | Unavailable | - | ||
| 6.10 | 6.10.1 | Expired | |||
| 6.9 | 6.9.0 | Expired | |||
| 6.8 | 6.8.4 | LTS | |||
| 6.7 | 6.7.0 | Expired | |||
| 6.6 | 6.6.0 | Expired | |||
| 6.5 | 6.5.0 | Expired | |||
| 6.4 | 6.4.0 | Soon | LTS | ||
| 6.3 | 6.3.0 | Expired | |||
| 6.2 | 6.2.0 | Expired | |||
| 6.1 | 6.1.0 | Expired | |||
| 6.0 | 6.0.1 | Expired | |||
| 5.12 | 5.12.0 | Expired | LTS | ||
| 5.11 | 5.11.1 | Expired | |||
| 5.10 | 5.10.2 | Expired | |||
| 5.9 | 5.9.0 | Expired | |||
| 5.8 | 5.8.0 | Expired | LTS | ||
| 5.7 | 5.7.0 | Expired | |||
| 5.6 | 5.6.0 | Expired | |||
| 5.5 | 5.5.0 | Expired | |||
| 5.4 | 5.4.1 | Expired | LTS | ||
| 5.3 | 5.3.0 | Expired | |||
| 5.2 | 5.2.0 | Expired | |||
| 5.1 | 5.1.2 | Expired | |||
| 5.0 | 5.0.0 | Expired | |||
| 4.12 | 4.12.4 | Expired | LTS | ||
| 4.8 | 4.8.6 | Expired | LTS | ||
| 4.4 | 4.4.5 | Expired | LTS | ||
| 3.28 | 3.28.12 | Expired | LTS | ||
| 3.24 | 3.24.7 | Expired | LTS | ||
| 3.20 | 3.20.7 | Expired | LTS | ||
| 3.16 | 3.16.10 | Expired | LTS | ||
| 3.12 | 3.12.4 | Expired | LTS | ||
| 3.8 | 3.8.3 | Expired | LTS | ||
| 3.4 | 3.4.8 | Expired | LTS | ||
| 2.18 | 2.18.3 | Expired | LTS | ||
| 2.16 | 2.16.4 | Expired | LTS | ||
| 2.12 | 2.12.2 | Expired | LTS | ||
| 2.8 | 2.8.3 | Expired | LTS | ||
| 2.4 | 2.4.6 | Expired | LTS |
Maintained Soon (≤ 180 days) Expired
Subscribe lifecycle: RSS · RSS (expired) · ICS
Subscribe CVEs: RSS for “Ember” · RSS (High+Critical only)
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
The Ember ZNet stack’s packet buffer manager may read out of bound memory leading to an assert, causing a Denial of Service (DoS).
A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert
A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert
High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.
Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko S…
Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis si…
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored i…
TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outsi…
A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.
A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.
In general, Ember.js escapes or strips any user-supplied content before inserting it in strings that will be sent to innerHTML. However, the `tagName` property of an `Ember.View` was inserted into su…
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leverag…
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leverag…
Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2.
Cross-site scripting (XSS) vulnerability in Ember.js 1.8.x through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before 1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2, and 2.2.x before…
Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1.4.x before 1.4.0-beta.6, when used in non-block form, allows remote attackers…
Ember 0.5.7 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.