CVE-2017-12465: Ccn-Lite
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
Multiple integer overflows in CCN-lite before 2.00 allow context-dependent attackers to have unspecified impact via vectors involving the (1) vallen variable in the iottlv_parse_sequence function or (2) typ, vallen and i variables in the localrpc_parse function.
Affected products
- Ccn-Lite Ccn-Lite: before 2.0.0 (fixed in 2.0.0)
Published 2018-02-07. Last modified 2026-06-17.