COVESA versions 2.18.8 and below suffer from heap buffer over-read and null pointer dereference vulnerabilities.