Vulnerability index

Browse CVEs

4,225 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Classic Buffer OverflowCWE-120 × clear
Core Ftp HIGH 7.5
CVE-2020-19595

Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.

No fix yet
Fix from $1,950 2021-04-05
Core Ftp CRITICAL 9.8
CVE-2020-19596

Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.

No fix yet
Fix from $2,300 2021-04-05
Core Ftp MEDIUM 5.5
CVE-2020-21588

Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Username editb…

Mitigation only
Fix from $1,600 2021-04-02
Ipados HIGH 7.8
CVE-2021-1763

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security…

Fix: 10.14.6 / 10.15.7+
Fix from $1,950 2021-04-02
Ipados HIGH 7.8
CVE-2020-9962

A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security U…

Fix: 7.0 / 10.14.6+
Fix from $1,950 2021-04-02
Libzmq HIGH 8.1
CVE-2021-20235EPSS 44%

There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator could have its sized changed…

Fix: 4.3.3+
Fix from $1,950 2021-04-01
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2021-22992EPSS 73%

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x b…

Fix: 11.6.5.3 / 12.1.5.3+
Fix from $2,300 2021-03-31
Ffmpeg HIGH 7.8
CVE-2020-24995

Buffer overflow vulnerability in sniff_channel_order function in aacdec_template.c in ffmpeg 3.1.2, allows attackers to execute arbitrary code (local…

Patch available
Fix from $1,950 2021-03-30
Instant CRITICAL 9.8
CVE-2019-5319

A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4…

Fix: 6.5.4.17 / 8.3.0.13+
Fix from $2,300 2021-03-30
Instant CRITICAL 9.8
CVE-2021-25149

A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4…

Fix: 6.5.4.17 / 8.3.0.13+
Fix from $2,300 2021-03-30
Phaser 6510 Firmware CRITICAL 9.8
CVE-2021-28672

Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), WorkCentre 6515 before 65.65.51 and 65.59.11 (Bridge), VersaLink B400 before 37.65.51 and 37…

Fix: 32.59.01 / 32.65.51+
Fix from $2,300 2021-03-29
Instant HIGH 8.8
CVE-2021-25144

A remote buffer overflow vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4…

Fix: 6.5.4.17 / 8.3.0.13+
Fix from $1,950 2021-03-29
FreeBSD CRITICAL 9.8
CVE-2020-25577

In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 rtsold(…

Mitigation only
Fix from $2,300 2021-03-29
FreeBSD CRITICAL 9.8
CVE-2020-25583

In FreeBSD 12.2-STABLE before r368250, 11.4-STABLE before r368253, 12.2-RELEASE before p1, 12.1-RELEASE before p11 and 11.4-RELEASE before p5 when pr…

Mitigation only
Fix from $2,300 2021-03-29
Arcgis Server MEDIUM 6.8
CVE-2021-29094

Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated att…

Fix: after 10.8.1
Fix from $1,600 2021-03-25
Enterprise Linux CRITICAL 9.8
CVE-2021-3466EPSS 9%

A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attac…

Patch available
Fix from $2,300 2021-03-25
Micrologix 1400 Firmware HIGH 8.6
CVE-2021-22659

Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allo…

Fix: after 21.6
Fix from $1,950 2021-03-25
Aironet Access Point Software HIGH 7.4
CVE-2021-1439

A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, adjacent a…

Fix: 17.3.3+
Fix from $1,950 2021-03-24
R6700 Firmware HIGH 8.8
CVE-2021-29068

Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects R6700v3 before 1.0.4.98, R6400v2 before 1.0.4.98, R7…

Fix: 1.0.1.62 / 1.0.2.16+
Fix from $1,950 2021-03-23
Linux Kernel MEDIUM 6.7
CVE-2021-28972

In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writ…

Fix: 4.4.263 / 4.14.227+
Fix from $1,600 2021-03-22
Linux Kernel HIGH 7.8
CVE-2021-28952

An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpec…

Fix: after 5.11.8
Fix from $1,950 2021-03-20
Apq8009 Firmware CRITICAL 9.8
CVE-2020-11299

Buffer overflow can occur in video while playing the non-standard clip in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Co…

Mitigation only
Fix from $2,300 2021-03-17
Zynq 7000s Firmware MEDIUM 6.8
CVE-2021-27208

When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when reading in any parameters in…

Mitigation only
Fix from $1,600 2021-03-15
Db2 HIGH 7.8
CVE-2020-5025

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 db2fm is vulnerable to a buffer overflow, caused by…

Fix: 11.1.4.6 / 11.5.5.0+
Fix from $1,950 2021-03-11
Gs116e Firmware HIGH 7.2
CVE-2020-35227

A buffer overflow vulnerability in the access control section on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices (in the administration web panel) allows…

Mitigation only
Fix from $1,950 2021-03-10
Gs116e Firmware MEDIUM 6.5
CVE-2020-35224

A buffer overflow vulnerability in the NSDP protocol authentication method on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote unauthenticat…

Mitigation only
Fix from $1,600 2021-03-10
Gs116e Firmware MEDIUM 6.8
CVE-2020-35225

The NSDP protocol implementation on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices was not properly validating the length of string parameters sent in w…

Mitigation only
Fix from $1,600 2021-03-10
Dragon Center CRITICAL 9.8
CVE-2021-27965EPSS 12%

The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privilege escalation via a crafted 0x…

Fix: 2.0.98.0+
Fix from $2,300 2021-03-05
Dx600a Firmware HIGH 7.5
CVE-2021-25306

A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by …

Mitigation only
Fix from $1,950 2021-03-02
Clearpass Policy Manager MEDIUM 5.3
CVE-2020-7120

A local authenticated buffer overflow vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF…

Fix: 6.8.8 / 6.9.3+
Fix from $1,600 2021-02-23