Vulnerability index

Browse CVEs

4,225 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Classic Buffer OverflowCWE-120 × clear
Xnview HIGH 7.8
CVE-2021-28835

Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.

Fix: 2.50+
Fix from $1,950 2023-08-11
Jhead HIGH 7.8
CVE-2020-28840

Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial…

Fix: 3.04+
Fix from $1,950 2023-08-11
Pdf Reader MEDIUM 5.5
CVE-2020-35990

Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows loc…

Fix: after 10.1.0.37527
Fix from $1,600 2023-08-11
Ffjpeg HIGH 7.8
CVE-2020-24222

Buffer Overflow vulnerability in jfif_decode() function in rockcarry ffjpeg through version 1.0.0, allows local attackers to execute arbitrary code d…

Fix: after 1.0.0
Fix from $1,950 2023-08-11
Mdadm MEDIUM 6.7
CVE-2023-28736

Buffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalation of priv…

Fix: 4.2+
Fix from $1,600 2023-08-11
Mp3 Audio Converter CRITICAL 9.8
CVE-2023-37734

EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.

No fix yet
Fix from $2,300 2023-08-10
Qcn7606 Firmware CRITICAL 9.8
CVE-2023-28561

Memory corruption in QESL while processing payload from external ESL device to firmware.

Mitigation only
Fix from $2,300 2023-08-08
Apq8096au Firmware HIGH 7.8
CVE-2023-21649

Memory corruption in WLAN while running doDriverCmd for an unspecific command.

Patch available
Fix from $1,950 2023-08-08
Libqb CRITICAL 9.8
CVE-2023-39976

log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.

Fix: 2.0.8+
Fix from $2,300 2023-08-08
Jwnr2000v2 Firmware HIGH 8.8
CVE-2023-39550

Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and …

No fix yet
Fix from $1,950 2023-08-07
Xr300 Firmware HIGH 8.8
CVE-2023-36499

Netgear XR300 v1.0.3.78 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at genie_ap_wifi_change.cgi.

No fix yet
Fix from $1,950 2023-08-07
R6900p Firmware HIGH 8.8
CVE-2023-38412

Netgear R6900P v1.3.3.154 was discovered to contain multiple buffer overflows via the wla_ssid and wlg_ssid parameters at ia_ap_setting.cgi.

No fix yet
Fix from $1,950 2023-08-07
Dg834gv5 Firmware HIGH 8.8
CVE-2023-38591

Netgear DG834Gv5 1.6.01.34 was discovered to contain multiple buffer overflows via the wla_ssid and wla_temp_ssid parameters at bsw_ssid.cgi.

No fix yet
Fix from $1,950 2023-08-07
Jwnr2000v2 Firmware HIGH 8.8
CVE-2023-38922

Netgear JWNR2000v2 v1.0.0.11, XWN5001 v0.4.1.1, and XAVN2001v2 v0.4.0.7 were discovered to contain multiple buffer overflows via the http_passwd and …

Mitigation only
Fix from $1,950 2023-08-07
Dgn3500 Firmware MEDIUM 6.5
CVE-2023-38924

Netgear DGN3500 1.1.00.37 was discovered to contain a buffer overflow via the http_password parameter at setup.cgi.

Mitigation only
Fix from $1,600 2023-08-07
Dc112a Firmware HIGH 8.8
CVE-2023-38925EPSS 15%

Netgear DC112A 1.0.0.64, EX6200 1.0.3.94 and R6300v2 1.0.4.8 were discovered to contain a buffer overflow via the http_passwd parameter in password.c…

Mitigation only
Fix from $1,950 2023-08-07
Ex6200 Firmware HIGH 8.8
CVE-2023-38926

Netgear EX6200 v1.0.3.94 was discovered to contain a buffer overflow via the wla_temp_ssid parameter at acosNvramConfig_set.

No fix yet
Fix from $1,950 2023-08-07
Odoh Rs MEDIUM 5.9
CVE-2023-3766

A vulnerability was discovered in the odoh-rs rust crate that stems from faulty logic during the parsing of encrypted queries. This issue specificall…

Fix: 1.0.2+
Fix from $1,600 2023-08-03
C80 Firmware CRITICAL 9.8
CVE-2023-3346

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker…

Mitigation only
Fix from $2,300 2023-08-03
Brocade Fabric Operating System MEDIUM 5.5
CVE-2023-31430

A buffer overflow vulnerability in “secpolicydelete” command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenti…

Fix: 9.1.1c+
Fix from $1,600 2023-08-02
Brocade Fabric Operating System MEDIUM 5.5
CVE-2023-31431

A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated us…

Fix: 9.1.1c+
Fix from $1,600 2023-08-02
FreeBSD HIGH 8.8
CVE-2023-3494

The fwctl driver implements a state machine which is executed when a bhyve guest accesses certain x86 I/O ports. The interface lets the guest copy a…

Mitigation only
Fix from $1,950 2023-08-01
Enterprise Linux MEDIUM 5.5
CVE-2023-38559

A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a den…

Fix: 10.02.0+
Fix from $1,600 2023-08-01
Firefox HIGH 7.5
CVE-2023-4055

When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expecte…

Fix: 102.14 / 115.1+
Fix from $1,950 2023-08-01
Ipados HIGH 8.8
CVE-2023-38590

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS …

Fix: 9.6 / 11.7.9+
Fix from $1,950 2023-07-28
Sumatrapdf MEDIUM 5.5
CVE-2023-33802

A buffer overflow in SumatraPDF Reader v3.4.6 allows attackers to cause a Denial of Service (DoS) via a crafted text file.

No fix yet
Fix from $1,600 2023-07-26
Paddlepaddle CRITICAL 9.8
CVE-2023-38671

Heap buffer overflow in paddle.trace in PaddlePaddle before 2.5.0. This flaw can lead to a denial of service, information disclosure, or more damage …

Fix: 2.5.0+
Fix from $2,300 2023-07-26
Arubaos CRITICAL 9.8
CVE-2023-35980

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…

Fix: 6.4.4.8-4.2.4.22 / 6.5.4.25+
Fix from $2,300 2023-07-25
Arubaos CRITICAL 9.8
CVE-2023-35981

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…

Fix: 6.4.4.8-4.2.4.22 / 6.5.4.25+
Fix from $2,300 2023-07-25
Arubaos CRITICAL 9.8
CVE-2023-35982

There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending special…

Fix: 6.4.4.8-4.2.4.22 / 6.5.4.25+
Fix from $2,300 2023-07-25