Comparison Overview
Department of Defense Office of Small Business Programs

Department of Defense Office of Small Business Programs
Pentagon - 3B941, Arlington, US
Last Update: 19/03/2026
Mission: To modernize the defense industrial base, accelerate acquisitions, and reestablish deterrence by reducing barriers for small businesses to supply our Warfighters with innovative solutions and critical services. Vision: Maximize opportunities for businesses to...

US Navy
1200 Navy Pentagon, Washington, 20350, US
Last Update: 02/04/2026
The United States is a maritime nation, and the U.S. Navy protects America at sea. Alongside our allies and partners, we defend freedom, preserve economic prosperity, and keep the seas open and free. Our nation is engaged in long-term competition. To defend American int...
Compliance Ranges Comparison

Department of Defense Office of Small Business Programs







US Navy






Benchmark & Cyber Underwriting Signals
Incidents vs Armed Forces Industry Avg (This Year)
No incidents recorded for Department of Defense Office of Small Business Programs in 2026.
Incidents vs Armed Forces Industry Avg (This Year)
No incidents recorded for US Navy in 2026.
Incident History - Department of Defense Office of Small Business Programs (X = Date, Y = Severity)
Department of Defense Office of Small Business Programs cyber incidents detection timeline including parent company and subsidiaries.
Incident History - US Navy (X = Date, Y = Severity)
US Navy cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Department of Defense Office of Small Business Programs

US Navy
FAQ
Latest Global CVEs
MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directory. Attackers can supply crafted alog files with backslash sequences in variable names to escape the output directory and append to arbitrary files on Windows systems.
- https://github.com/moos-ivp/moos-ivp
- https://github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed2472971b/ivp/src/lib_logutils/SplitHandler.cpp#L189
- https://github.com/moos-ivp/moos-ivp/commit/6f0619e905b325d6b88f76425673045c6e4f6f94
- https://github.com/moos-ivp/moos-ivp/pull/137
- https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-alog-splitting-path-traversal-on-windows
MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication.
- https://github.com/themoos/core-moos
- https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/Comms/MOOSCommPkt.cpp#L228
- https://github.com/themoos/core-moos/commit/d30c14585753f9ae39749d9628ed15c8383f0568
- https://github.com/themoos/core-moos/pull/75
- https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-out-of-bounds-read-via-short-packet
MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-length telegram to trigger the off-by-one write, corrupting the stack and potentially enabling code execution.
- https://github.com/themoos/core-moos
- https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/Utils/MOOSSerialPort.cpp#L595
- https://github.com/themoos/core-moos/commit/befb04df2039d0080715ea35f56268092db4ec0f
- https://github.com/themoos/core-moos/pull/73
- https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-off-by-one-buffer-overflow-in-serial-telegram-handling
MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the browser of operators viewing the web interface.
- https://github.com/themoos/core-moos
- https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/DB/HTTPConnection.cpp#L460
- https://github.com/themoos/core-moos/commit/a3f26f099bb08decb143f704d8b1ca16ae405b44
- https://github.com/themoos/core-moos/pull/78
- https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-http-pages-stored-cross-site-scripting
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution.
- https://github.com/themoos/ui-moos
- https://github.com/themoos/ui-moos/blob/50b9c6c65169c501f746cfef1e167f74a7735e74/Tools/Graphical/uMS/ScopeTabPane.cpp#L243
- https://github.com/themoos/ui-moos/commit/a6ebc0bc6cb360315ce620e865f996d189cddb0e
- https://github.com/themoos/ui-moos/pull/5
- https://www.vulncheck.com/advisories/moos-ui-moos-through-50b9c6c-ums-buffer-overflow-via-long-moos-identifiers