← Vulnerability feed

Vulnerability record · CVE-2023-43628 · published 5 December 2023

CVE-2023-43628: Gpsd project gpsd vulnerability

Gpsd Project · Gpsd

An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability.

7.5 CVSS 3.1 High EPSS 1.2% · top 32.4% CWE-191 · CWE-191
7.5CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-43628 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-67268Gpsd project gpsd heap-based buffer overflow vulnerabilitygpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, wh…EPSS 0.77%8.8CVE-2018-17937Gpsd project gpsd stack-based buffer overflow vulnerabilitygpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote att…EPSS 2.7%8.4CVE-2026-58459Gpsd project gpsd os command injection vulnerabilitygpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS…EPSS 2.9%7.5CVE-2025-67269Gpsd project gpsd vulnerabilityAn integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e5…EPSS 0.55%4.3CVE-2013-2038Gpsd project gpsd improper input validation vulnerabilityThe NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon termination) and possibly execute arbitrary code …EPSS 4.2%9.8CVE-2014-0497Adobe Flash Player integer underflow allows remote code executionAdobe Flash Player contains an integer underflow (CWE-191) that allows remote attackers to execute arbitrary code via unspecified vectors. The flaw a…KEVEPSS 100%analysed8.4CVE-2022-0185Linux Kernel Filesystem Context Heap Buffer OverflowThe legacy_parse_param function in the Linux kernel's Filesystem Context functionality fails to properly verify supplied parameter lengths, causing a…KEVEPSS 25%analysed7.8CVE-2021-31956Windows NTFS integer underflow privilege escalationCVE-2021-31956 is an elevation of privilege flaw in the Windows NTFS file system driver, rooted in an integer underflow (CWE-191). A local attacker w…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2023-43628), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.