Keith Cullen maintains FreeCoAP, a focused implementation of the Constrained Application Protocol (CoAP) for resource-constrained IoT and embedded devices. The observed vulnerability exposure in this narrow product scope reflects the protocol-parsing and network-handling demands inherent to CoAP implementations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keith Cullen over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-40493CRITICAL Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attackers to cause a denial of service and potentially execute arb | Oct 22, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-40494CRITICAL Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service (stack buffer overflow) via a crafted packet. | Oct 22, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-31030CRITICAL An issue in coap_msg.c in Keith Cullen's FreeCoAP v.0.7 allows remote attackers to cause a Denial of Service or potentially disclose information via a specially crafted packet. | May 31, 2024 | 9.1 | 25 | NO | NO |
CVE-2024-31029HIGH An issue in the server_handle_regular function of the test_coap_server.c file within the FreeCoAP project allows remote attackers to cause a Denial of Service through specially cra | Oct 22, 2024 | 8.2 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keith Cullen.
Media articles that mention a CVE ID that affects a product developed by Keith Cullen — matched by CVE ID, not by vendor name.