Wind River Systems maintains a narrow but strategically important portfolio of embedded real-time operating systems and platform software, with VxWorks, a foundational real-time OS deployed across industrial control, aerospace, and critical infrastructure environments, representing the dominant exposure vector. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity and a notable tendency to acquire public exploit code, reflecting the memory-safety challenges inherent to large C-based kernel codebases and the high-value nature of compromising embedded control systems. The recurring weakness classes—improper input validation, classic buffer overflows, out-of-bounds writes, and integer overflows—are characteristic of low-level systems programming and concentrate in protocol parsers, device drivers, and network-facing components that frequently operate with elevated privilege in production deployments. Defenders should track this vendor's advisories closely and prioritize patching for internet-accessible or network-adjacent instances, particularly in operational technology and critical infrastructure contexts where remediation cycles may be constrained. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wind River Systems Inc. over time
Of all the CVEs published by Wind River Systems Inc. as a CNA, 0.0% affect products that Wind River Systems Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Wind River Systems Inc., 0.0% are self-published by Wind River Systems Inc. as a CNA.
Signals from CVEs in this vendor scope (48 CVEs).
48 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12255CRITICAL Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. | Aug 9, 2019 | 9.8 | 81 | NO | YES |
CVE-2002-1337HIGH Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments a | Mar 7, 2003 | 10.0 | 80 | NO | YES |
CVE-2019-12257HIGH Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdh | Aug 9, 2019 | 8.8 | 74 | NO | NO |
CVE-2010-2965CRITICAL The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other produc | Aug 5, 2010 | 9.8 | 61 | NO | NO |
CVE-2019-12258HIGH Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. | Aug 9, 2019 | 7.5 | 48 | NO | YES |
CVE-2019-12265MEDIUM Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 | Aug 9, 2019 | 5.3 | 48 | NO | NO |
CVE-2019-12256CRITICAL Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options. | Aug 9, 2019 | 9.8 | 45 | NO | NO |
CVE-2019-12260CRITICAL Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a ma | Aug 9, 2019 | 9.8 | 43 | NO | NO |
CVE-2007-4938HIGH Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbi | Sep 18, 2007 | 7.6 | 36 | NO | YES |
CVE-2007-2736HIGH PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_atkroot parameter. | May 17, 2007 | 10.0 | 36 | NO | YES |
Signals from CVEs in this vendor scope (48 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wind River Systems Inc..
Media articles that mention a CVE ID that affects a product developed by Wind River Systems Inc. — matched by CVE ID, not by vendor name.