Vulnerability index

Browse CVEs

3,570 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Stack-based Buffer OverflowCWE-121 × clear
Debian Linux HIGH 8.1
CVE-2022-41981

A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0. A specially-crafted targa file can lead to…

No fix yet
Fix from $1,950 2022-12-22
Android MEDIUM 5.5
CVE-2022-39106

In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

Mitigation only
Fix from $1,600 2022-12-06
Android MEDIUM 5.5
CVE-2022-39129

In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

No fix yet
Fix from $1,600 2022-12-06
Kernel HIGH 8.2
CVE-2022-36337

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads …

Fix: after 5.5
Fix from $1,950 2022-11-23
W15e Firmware HIGH 7.5
CVE-2022-42060

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows …

No fix yet
Fix from $1,950 2022-11-15
Xpdf MEDIUM 5.5
CVE-2022-43295

XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.

Mitigation only
Fix from $1,600 2022-11-14
Fedora MEDIUM 6.5
CVE-2022-41854

Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied i…

Fix: 1.32+
Fix from $1,600 2022-11-11
Jt2go HIGH 7.8
CVE-2022-41664

A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visu…

Fix: 13.3.0.7 / 14.0.0.3+
Fix from $1,950 2022-11-08
H0 Ecom100 Firmware MEDIUM 6.5
CVE-2022-3228

Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing a stack-based buffer overflo…

Fix: 5.0.156+
Fix from $1,600 2022-10-28
R Seenet CRITICAL 9.8
CVE-2022-3385

Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stac…

Fix: after 2.4.17
Fix from $2,300 2022-10-27
R Seenet CRITICAL 9.8
CVE-2022-3386

Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename t…

Fix: after 2.4.17
Fix from $2,300 2022-10-27
Openbmc HIGH 7.5
CVE-2022-3409

A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified during mitigation for CVE-2022…

Fix: after 2.13.0
Fix from $1,950 2022-10-27
Iota All In One Security Kit Firmware CRITICAL 9.8
CVE-2022-32454

A stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.…

No fix yet
Fix from $2,300 2022-10-25
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26727

Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker…

Mitigation only
Fix from $2,300 2022-10-24
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26728

Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arb…

Mitigation only
Fix from $2,300 2022-10-24
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26729

Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker t…

Mitigation only
Fix from $2,300 2022-10-24
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26730

A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allows an attacker to execute arbi…

Mitigation only
Fix from $2,300 2022-10-24
Iac Ast2500a Firmware CRITICAL 9.8
CVE-2021-26731

Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticate…

Mitigation only
Fix from $2,300 2022-10-24
Iowow HIGH 7.5
CVE-2022-23462

IOWOW is a C utility library and persistent key/value storage engine. Versions 1.4.15 and prior contain a stack buffer overflow vulnerability that al…

Fix: after 1.4.15
Fix from $1,950 2022-10-21
Acrobat Dc HIGH 7.8
CVE-2022-42339

Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability t…

Fix: 20.005.30407 / 22.003.20258+
Fix from $1,950 2022-10-14
Acrobat Dc HIGH 7.8
CVE-2022-38450

Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability t…

Fix: 20.005.30407 / 22.003.20258+
Fix from $1,950 2022-10-14
Coldfusion CRITICAL 9.8
CVE-2022-35710EPSS 43%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could r…

Patch available
Fix from $2,300 2022-10-14
Coldfusion CRITICAL 9.8
CVE-2022-35690EPSS 72%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could r…

Patch available
Fix from $2,300 2022-10-14
Android MEDIUM 5.5
CVE-2022-38672

In face detect driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service in kernel.

Mitigation only
Fix from $1,600 2022-10-14
Alienware Area 51m R1 Firmware HIGH 7.8
CVE-2022-32493

Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by u…

Fix: 1.0.16 / 1.0.20+
Fix from $1,950 2022-10-12
Sap Iq CRITICAL 9.8
CVE-2022-35299

SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical errors in memory management to cause a memory corr…

Mitigation only
Fix from $2,300 2022-10-11
Threadx Usbx CRITICAL 9.8
CVE-2022-36063

Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and available for all Azure RTOS …

Fix: 6.1.11+
Fix from $2,300 2022-10-10
Commons Jxpath MEDIUM 6.5
CVE-2022-40160

** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to…

Fix: after 1.3
Fix from $1,600 2022-10-06
Commons Jxpath MEDIUM 6.5
CVE-2022-40159

** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to…

Fix: after 1.3
Fix from $1,600 2022-10-06
Fedora HIGH 7.8
CVE-2022-3324

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.

Fix: 9.0.0598+
Fix from $1,950 2022-09-27