Vulnerability index

Browse CVEs

4,225 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Classic Buffer OverflowCWE-120 × clear
Traffix Signaling Delivery Controller HIGH 7.0
CVE-2018-14879

The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Tcpdump HIGH 7.8
CVE-2018-16301

The command-line argument parser in tcpdump before 4.99.0 has a buffer overflow in tcpdump.c:read_infile(). To trigger this vulnerability the attacke…

Fix: 4.99.0+
Fix from $1,950 2019-10-03
Ipq8074 Firmware CRITICAL 9.8
CVE-2019-10539

Possible buffer overflow issue due to lack of length check when parsing the extended cap IE header length in Snapdragon Auto, Snapdragon Compute, Sna…

Mitigation only
Fix from $2,300 2019-09-30
Ipq8074 Firmware CRITICAL 9.8
CVE-2019-10540

Buffer overflow in WLAN NAN function due to lack of check of count value received in NAN availability attribute in Snapdragon Auto, Snapdragon Comput…

Mitigation only
Fix from $2,300 2019-09-30
Mdm9650 Firmware CRITICAL 9.8
CVE-2019-2252

Classic buffer overflow vulnerability while playing the specific video whose Decode picture buffer size is more than 16 in Snapdragon Auto, Snapdrago…

Patch available
Fix from $2,300 2019-09-30
Mdm9150 Firmware HIGH 7.8
CVE-2019-2333

Buffer overflow due to improper validation of buffer size while IPA driver processing to perform read operation in Snapdragon Auto, Snapdragon Comput…

Patch available
Fix from $1,950 2019-09-30
Mdm9150 Firmware HIGH 7.8
CVE-2019-2341

Buffer overflow when the audio buffer size provided by user is larger than the maximum allowable audio buffer size. in Snapdragon Auto, Snapdragon Co…

Patch available
Fix from $1,950 2019-09-30
Mdm9150 Firmware HIGH 7.8
CVE-2019-10498

Buffer overflow scenario if the client sends more than 5 io_vec requests to the server in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IO…

Mitigation only
Fix from $1,950 2019-09-30
Mdm9150 Firmware HIGH 7.8
CVE-2019-10508

Lack of input validation for data received from user space can lead to OOB access in WLAN in Snapdragon Auto, Snapdragon Consumer Electronics Connect…

Patch available
Fix from $1,950 2019-09-30
Netskope HIGH 7.8
CVE-2019-10882

The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from loca…

Fix: 57.2.0.219 / 60.2.0.214+
Fix from $1,950 2019-09-26
iOS HIGH 7.5
CVE-2019-12655

A vulnerability in the FTP application layer gateway (ALG) functionality used by Network Address Translation (NAT), NAT IPv6 to IPv4 (NAT64), and the…

Fix: 16.3.8 / 16.11.1+
Fix from $1,950 2019-09-25
Irfanview HIGH 7.8
CVE-2019-16887

In IrfanView 4.53, Data from a Faulting Address controls a subsequent Write Address starting at image00400000+0x000000000001dcfc.

No fix yet
Fix from $1,950 2019-09-25
File Sharing Wizard CRITICAL 9.8
CVE-2019-16724EPSS 72%

File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer…

No fix yet
Fix from $2,300 2019-09-24
Fx0 Gpnt00000 Firmware HIGH 7.5
CVE-2019-14753

SICK FX0-GPNT00000 and FX0-GENT00000 devices through 3.4.0 have a Buffer Overflow

Fix: after 3.4.0
Fix from $1,950 2019-09-24
Linux Kernel CRITICAL 9.8
CVE-2019-16746EPSS 13%

An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon h…

Fix: 3.16.79 / 4.4.197+
Fix from $2,300 2019-09-24
Integard Pro CRITICAL 9.8
CVE-2019-16702EPSS 11%

Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs parameter to the /LoginAdmin UR…

No fix yet
Fix from $2,300 2019-09-23
Ipc Hdw1x2x Firmware CRITICAL 9.8
CVE-2019-9677

The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malici…

Fix: 2019-08-18+
Fix from $2,300 2019-09-18
Asuswrt Merlin HIGH 7.5
CVE-2018-20336

An issue was discovered in ASUSWRT 3.0.0.4.384.20308. There is a stack-based buffer overflow issue in parse_req_queries function in wanduck.c via a l…

No fix yet
Fix from $1,950 2019-09-17
Linux Kernel HIGH 7.8
CVE-2019-14835

A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers t…

Fix: 3.16.74 / 4.4.193+
Fix from $1,950 2019-09-17
Fedora CRITICAL 9.8
CVE-2019-16239

process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.

Fix: 8.05+
Fix from $2,300 2019-09-17
Integard Home CRITICAL 9.8
CVE-2010-5333EPSS 16%

The web server in Integard Pro and Home before 2.0.0.9037 and 2.2.x before 2.2.0.9037 has a buffer overflow via a long password in an administration …

Fix: 2.0.0.9037 / 2.2.0.9037+
Fix from $2,300 2019-09-13
Vxworks CRITICAL 9.8
CVE-2019-12260EPSS 23%

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer…

Fix: 2.2.1 / 6.9.4.12+
Fix from $2,300 2019-08-09
Vxworks CRITICAL 9.8
CVE-2019-12261EPSS 9%

Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urg…

Fix: 2.2.1 / 6.9.4.12+
Fix from $2,300 2019-08-09
Vxworks CRITICAL 9.8
CVE-2019-12255EPSS 75%

Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that lea…

Fix: 2.2.1 / 6.9.4+
Fix from $2,300 2019-08-09
Vxworks CRITICAL 9.8
CVE-2019-12256EPSS 27%

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing o…

Fix: 2.2.1 / 6.9.4.12+
Fix from $2,300 2019-08-09
Vxworks HIGH 8.8
CVE-2019-12257EPSS 84%

Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHC…

Fix: 6.9.4 / 7.59+
Fix from $1,950 2019-08-09
Cherokee Web Server HIGH 7.5
CVE-2019-1010218

Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CWE-120. The impact is: Crash. …

Fix: after 1.2.103
Fix from $1,950 2019-07-22
Laserjet Pro M280 M281 T6b80a Firmware CRITICAL 9.8
CVE-2019-6327

HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) ma…

Fix: 20190419 / 20190426+
Fix from $2,300 2019-06-17
Vlc Media Player MEDIUM 6.5
CVE-2019-5439EPSS 5%

A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit.

Fix: 3.0.7+
Fix from $1,600 2019-06-13
Idrac6 Firmware CRITICAL 9.8
CVE-2019-3705

Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21.20, 3.21.24.22, 3.21.26.22 a…

Fix: 2.61.60.60 / 2.92+
Fix from $2,300 2019-04-26