CCN Lite is a research-focused named data networking implementation with a narrowly scoped product portfolio that has achieved prominence within specialized networking and information-centric networking research communities. The vendor's vulnerability profile reflects its role as an experimental platform rather than a production deployment—disclosures are sparse and distributed across the codebase without a distinctive concentration in particular weakness classes. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ccn Lite over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-12468CRITICAL Buffer overflow in ccn-lite-ccnb2xml.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors involving the vallen and len variables. | Feb 7, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-7039CRITICAL CCN-lite 2.0.0 Beta allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact because the ccnl_ndntlv_prependBlob function in | Feb 14, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-12889CRITICAL An issue was discovered in CCN-lite 2.0.1. There is a heap-based buffer overflow in mkAddToRelayCacheRequest and in ccnl_populate_cache for an array lacking '\0' termination when r | Jun 26, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-6953CRITICAL In CCN-lite 2, the Parser of NDNTLV does not verify whether a certain component's length field matches the actual component length, which has a resultant buffer overflow and out-of | Feb 13, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-6948CRITICAL In CCN-lite 2, the function ccnl_prefix_to_str_detailed can cause a buffer overflow, when writing a prefix to the buffer buf. The maximal size of the prefix is CCNL_MAX_PREFIX_SIZE | Feb 13, 2018 | 9.8 | 29 | NO | NO |
CVE-2017-12466CRITICAL CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors related to ssl_halen when running ccn-lite-sim, which trigger an out-of-bounds access | Feb 7, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-12472CRITICAL ccnl-ext-mgmt.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging missing NULL pointer checks after ccnl_malloc. | Feb 7, 2018 | 9.8 | 27 | NO | NO |
CVE-2017-12471CRITICAL The cnb_parse_lev function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging failure to check for out-of-bounds conditions, which | Feb 7, 2018 | 9.8 | 27 | NO | NO |
CVE-2017-12470CRITICAL Integer overflow in the ndn_parse_sequence function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors involving the typ and vallen v | Feb 7, 2018 | 9.8 | 27 | NO | NO |
CVE-2017-12469CRITICAL Buffer overflow in util/ccnl-common.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging incorrect memory allocation. | Feb 7, 2018 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ccn Lite.
Media articles that mention a CVE ID that affects a product developed by Ccn Lite — matched by CVE ID, not by vendor name.