About “Ember”

A curated feed of “Ember”-related CVEs appears below. We currently track 19 CVEs for this tag (all time). In the last 365 days, 1 were published. Average CVSS is 5.9 (all time; 5.9 over 365d), and 11% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-252 - Unchecked Return Value.

In our taxonomy this topic maps to a LOW impact class. Language runtimes and libraries cascade through dependency graphs. Upgrade runtime and toolchain, pin versions, rebuild images, and enable SAST or DAST and linters. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.

Support & lifecycle: emberjs

This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.

CycleReleaseLatestPremier SupportEOLLTS
6.116.11.1Unavailable-
6.106.10.1 Expired
6.96.9.0 Expired
6.86.8.4LTS
6.76.7.0 Expired
6.66.6.0 Expired
6.56.5.0 Expired
6.46.4.0 SoonLTS
6.36.3.0 Expired
6.26.2.0 Expired
6.16.1.0 Expired
6.06.0.1 Expired
5.125.12.0 ExpiredLTS
5.115.11.1 Expired
5.105.10.2 Expired
5.95.9.0 Expired
5.85.8.0 ExpiredLTS
5.75.7.0 Expired
5.65.6.0 Expired
5.55.5.0 Expired
5.45.4.1 ExpiredLTS
5.35.3.0 Expired
5.25.2.0 Expired
5.15.1.2 Expired
5.05.0.0 Expired
4.124.12.4 ExpiredLTS
4.84.8.6 ExpiredLTS
4.44.4.5 ExpiredLTS
3.283.28.12 ExpiredLTS
3.243.24.7 ExpiredLTS
3.203.20.7 ExpiredLTS
3.163.16.10 ExpiredLTS
3.123.12.4 ExpiredLTS
3.83.8.3 ExpiredLTS
3.43.4.8 ExpiredLTS
2.182.18.3 ExpiredLTS
2.162.16.4 ExpiredLTS
2.122.12.2 ExpiredLTS
2.82.8.3 ExpiredLTS
2.42.4.6 ExpiredLTS

Maintained Soon (≤ 180 days) Expired

Subscribe lifecycle: RSS  ·  RSS (expired)  ·  ICS

Subscribe CVEs: RSS for “Ember”  ·  RSS (High+Critical only)

CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).

CVSS ≥ 0.0
2025-07-30
Medium

CVE-2025-1394

The Ember ZNet stack’s packet buffer manager may read out of bound memory leading to an assert, causing a Denial of Service (DoS).

2025-01-28
Medium

CVE-2024-6351

A malformed packet can cause a buffer overflow in the NWK/APS layer of the Ember ZNet stack and lead to an assert

2025-01-13
Medium

CVE-2024-6352

A malformed packet can cause a buffer overflow in the APS layer of the Ember ZNet stack and lead to an assert

2024-02-23
Medium

CVE-2023-51394

High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.

Medium

CVE-2023-51393

Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as part of Silicon Labs Gecko S…

Medium

CVE-2023-51392

Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis si…

2024-02-05
High

CVE-2023-6874

Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number

2023-10-26
Medium

CVE-2023-41096

Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network credentials stored i…

2023-10-04
Critical

CVE-2023-41094

TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outsi…

2022-11-18
Medium

CVE-2022-24939

A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

2022-11-14
Medium

CVE-2022-24938

A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

Medium

CVE-2022-24937

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.

2022-06-30
Medium

CVE-2013-4170

In general, Ember.js escapes or strips any user-supplied content before inserting it in strings that will be sent to innerHTML. However, the `tagName` property of an `Ember.View` was inserted into su…

2018-02-15
Medium

CVE-2014-0014

Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leverag…

Medium

CVE-2014-0013

Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leverag…

2017-09-20
Medium

CVE-2015-1866

Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2.

2017-04-13
Medium

CVE-2015-7565

Cross-site scripting (XSS) vulnerability in Ember.js 1.8.x through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before 1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2, and 2.2.x before…

2014-02-27
Low

CVE-2014-0046

Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1.4.x before 1.4.0-beta.6, when used in non-block form, allows remote attackers…

2010-10-20
Medium

CVE-2010-3355

Ember 0.5.7 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

CVE Daily Lookup — auto-links CVE IDs on any page you visit. GitHub, Jira, Confluence & more. Free.