Vendor
Memory Exhaustion Vulnerability in MOOS-IvP pMarineViewer
1 TTP 1 CVEAn unauthenticated memory exhaustion vulnerability in MOOS-IvP pMarineViewer (<= 24.8.1) allows attackers to stall the operator display by flooding the application with unbounded NODE_REPORT messages.
Resource Exhaustion in MOOS-IvP pRealm via REALMCAST_REQ
1 TTP 1 CVEMOOS-IvP pRealm version 24.8.1 and earlier is vulnerable to a denial-of-service attack due to improper validation of REALMCAST_REQ subscriptions, allowing attackers to exhaust system resources.
Identity Spoofing Vulnerability in MOOS-IvP uFldNodeComms
1 CVEThe uFldNodeComms component in MOOS-IvP versions up to 24.8.1 fails to validate node identity, allowing attackers to spoof packets and inject arbitrary variable notifications.
CVE-2026-85440: Heap Overflow in MOOS core-moos
5 TTPs 1 CVEA pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.
Buffer Overflow Vulnerabilities in MOOS-IvP
4 TTPs 1 CVEMultiple buffer overflow vulnerabilities in MOOS-IvP versions up to 24.8.1 allow for remote code execution via malformed IvP function strings.
Unauthenticated Bridge Redirection in MOOS-IvP uFldShoreBroker
1 TTP 1 CVEMOOS-IvP uFldShoreBroker through version 24.8.1 is vulnerable to unauthorized route manipulation via forged node ping messages, enabling attackers to redirect data to arbitrary network locations.
Authentication Bypass and Message Injection in MOOS pShare
2 TTPs 1 CVEThe pShare component in MOOS essential-moos versions up to 10.0.1 is vulnerable to unauthenticated UDP message injection and denial-of-service.
Command Injection in MOOS-IvP uMemWatch
1 TTP 1 CVEMOOS-IvP uMemWatch through version 24.8.1 is vulnerable to command injection due to improper sanitization of MOOS client names, allowing arbitrary code execution.
Remote Code Execution in MOOS-IvP iSay
1 rule 1 TTP 1 CVEThe iSay component in MOOS-IvP through 24.8.1 is vulnerable to remote code execution because it passes unsanitized SAY_MOOS variable content directly to a shell, allowing command injection via backticks or substitution syntax.