Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yocto Project

First CVE: Jun 16, 2017Active for: 9 yearsTotal CVEs: 27

The Yocto Project is a build framework and embedded Linux distribution system used to construct custom Linux images for embedded and IoT devices, with its core metadata and build tools (Pyro) representing the primary affected component. Documented vulnerabilities in this context center on information-disclosure weaknesses where sensitive configuration, credentials, or build artifacts become accessible to unauthorized parties—a risk inherent to build systems that aggregate diverse software components and configuration data. Current vulnerability counts, severity distribution, and any exploitation activity are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
Bottom 1%
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yocto Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2017
9 years ago
Most Recent CVE
May 15, 2023
1,166 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-26447CRITICAL
In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User
Sep 6, 20229.830NONO
CVE-2017-9731HIGH
In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive information by reading a URL in a Sourc
Jun 16, 20177.524NONO
CVE-2022-32633MEDIUM
In Wi-Fi, there is a possible memory access violation due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interacti
Dec 5, 20226.722NONO
CVE-2022-32632MEDIUM
In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User i
Dec 5, 20226.722NONO
CVE-2022-32631MEDIUM
In Wi-Fi, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User i
Dec 5, 20226.722NONO
CVE-2022-26465MEDIUM
In audio ipi, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. Us
Sep 6, 20226.722NONO
CVE-2022-26435MEDIUM
In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio
Aug 1, 20226.722NONO
CVE-2022-26433MEDIUM
In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio
Aug 1, 20226.722NONO
CVE-2022-26431MEDIUM
In mailbox, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User in
Aug 1, 20226.722NONO
CVE-2022-26430MEDIUM
In mailbox, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interactio
Aug 1, 20226.722NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
93%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local25 (92.6%)
Network2 (7.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (96.3%)
High1 (3.7%)
Unknown0 (0.0%)
User Interaction
None27 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High25 (92.6%)
None2 (7.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yocto Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yocto Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yocto Project's Products

View all 2 CNAs →

Top CWEs