Vulnerability index

Browse CVEs

4,225 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Classic Buffer OverflowCWE-120 × clear
Baseboard Management Controller Firmware HIGH 8.1
CVE-2019-11178

Stack overflow in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure and/…

Fix: 2.18+
Fix from $1,950 2019-11-14
Debian Linux HIGH 7.8
CVE-2011-1145

The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE para…

Fix: after 2.2.14
Fix from $1,950 2019-11-14
Cc256xc Bt Sp Firmware HIGH 8.8
CVE-2019-15948

Texas Instruments CC256x and WL18xx dual-mode Bluetooth controller devices, when LE scan mode is used, allow remote attackers to trigger a buffer ove…

Fix: after 4.4
Fix from $1,950 2019-11-13
My Cloud Ex2 Ultra Firmware HIGH 8.8
CVE-2019-18931

Western Digital My Cloud EX2 Ultra firmware 2.31.195 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via crafted GET/POST pa…

No fix yet
Fix from $1,950 2019-11-13
Debian Linux HIGH 7.8
CVE-2019-18397

A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to caus…

Fix: after 1.0.7
Fix from $1,950 2019-11-13
Debian Linux HIGH 8.8
CVE-2010-3844

An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.

Patch available
Fix from $1,950 2019-11-12
Mdm9206 Firmware CRITICAL 9.8
CVE-2019-10522

While playing the clip which is nonstandard buffer overflow can occur while parsing in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, …

Mitigation only
Fix from $2,300 2019-11-06
Mdm9607 Firmware CRITICAL 9.8
CVE-2019-10531

Incorrect reading of system image resulting in buffer overflow when size of system image is increased in Snapdragon Auto, Snapdragon Mobile, Snapdrag…

Patch available
Fix from $2,300 2019-11-06
Ipq4019 Firmware HIGH 7.8
CVE-2019-10491

ADSP can be compromised since it`s a general-purpose CPU processing untrusted data in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, S…

Patch available
Fix from $1,950 2019-11-06
Msm8909w Firmware HIGH 7.8
CVE-2019-10496

Lack of checking a variable received from driver and populating in Firmware data structure leads to buffer overflow in Snapdragon Auto, Snapdragon Co…

Mitigation only
Fix from $1,950 2019-11-06
Termpkg CRITICAL 9.8
CVE-2006-3100

termpkg 3.3 suffers from buffer overflow.

Patch available
Fix from $2,300 2019-11-06
Chicken HIGH 8.8
CVE-2013-2075

Multiple buffer overflows in the (1) R5RS char-ready, (2) tcp-accept-ready, and (3) file-select procedures in Chicken through 4.8.0.3 allows attacker…

Fix: after 4.8.0.3
Fix from $1,950 2019-10-31
Chicken HIGH 7.5
CVE-2012-6122

Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor …

Fix: 4.8.0.1+
Fix from $1,950 2019-10-31
Overkill CRITICAL 9.8
CVE-2009-5041

overkill has buffer overflow via long player names that can corrupt data on the server machine

Fix: 0.16-14.1+
Fix from $2,300 2019-10-31
Tightvnc CRITICAL 9.8
CVE-2019-8287EPSS 19%

TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially result code execution. This atta…

Mitigation only
Fix from $2,300 2019-10-29
Intrasrv CRITICAL 9.8
CVE-2019-17181EPSS 49%

A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET or HEAD request that can resul…

No fix yet
Fix from $2,300 2019-10-28
PHP CRITICAL 9.8
CVE-2019-11043 KEVEPSS 99%

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM modu…

Fix: 7.1.33 / 7.2.24+
Fix from $2,300 2019-10-28
Ip Security Camera Firmware CRITICAL 9.8
CVE-2016-2356

Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.

Fix: after 2016-11-14
Fix from $2,300 2019-10-25
Db2 High Performance Unload Load HIGH 7.8
CVE-2019-4523

IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds checking which could allow a l…

Mitigation only
Fix from $1,950 2019-10-22
Linux Kernel HIGH 8.8
CVE-2019-17666

rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer …

Fix: 3.16.77 / 4.4.199+
Fix from $1,950 2019-10-17
Dir 868l Firmware CRITICAL 9.8
CVE-2017-14948

Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary cod…

No fix yet
Fix from $2,300 2019-10-14
Xftp CRITICAL 9.8
CVE-2019-17320

NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name f…

Fix: after 6.0149
Fix from $2,300 2019-10-10
File Sharing Wizard CRITICAL 9.8
CVE-2019-17415

A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute …

No fix yet
Fix from $2,300 2019-10-09
Debian Linux MEDIUM 6.5
CVE-2019-17402

Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in cr…

Mitigation only
Fix from $1,600 2019-10-09
Irfanview HIGH 7.8
CVE-2019-17247

IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x0000000000007da8.

Mitigation only
Fix from $1,950 2019-10-08
Irfanview HIGH 7.8
CVE-2019-17243

IrfanView 4.53 allows Data from a Faulting Address to control Code Flow starting at JPEG_LS+0x0000000000003155.

Mitigation only
Fix from $1,950 2019-10-08
Irfanview HIGH 7.8
CVE-2019-17244

IrfanView 4.53 allows Data from a Faulting Address to control Code Flow starting at JPEG_LS+0x0000000000001d8a.

Mitigation only
Fix from $1,950 2019-10-08
Linux Kernel CRITICAL 9.8
CVE-2019-17133EPSS 7%

In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.

Fix: 3.16.77 / 4.4.198+
Fix from $2,300 2019-10-04
Libopenmpt CRITICAL 9.8
CVE-2019-17113

In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths…

Fix: 0.3.19 / 0.4.9+
Fix from $2,300 2019-10-04
Debian Linux HIGH 7.5
CVE-2019-15166

lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03