Vulnerability index

Browse CVEs

3,570 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Stack-based Buffer OverflowCWE-121 × clear
My Cloud Home Firmware MEDIUM 6.7
CVE-2022-23006

A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attack…

Fix: 8.10.0-117+
Fix from $1,600 2022-09-27
Fedora HIGH 7.8
CVE-2022-3296

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

Fix: 9.0.0577+
Fix from $1,950 2022-09-25
Gds3710 Firmware CRITICAL 9.8
CVE-2022-2025

an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param le…

Mitigation only
Fix from $2,300 2022-09-23
Gds3710 Firmware CRITICAL 9.8
CVE-2022-2070

In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf …

Mitigation only
Fix from $2,300 2022-09-23
Libiec61850 CRITICAL 9.8
CVE-2022-2970

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input be…

Fix: 1.5.0+
Fix from $2,300 2022-09-23
Libiec61850 CRITICAL 9.8
CVE-2022-2972

MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) is vulnerable to a stack-b…

Fix: 1.5.0+
Fix from $2,300 2022-09-23
Nuc M15 Laptop Kit Lapbc510 Firmware HIGH 8.2
CVE-2022-26873

A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitiga…

No fix yet
Fix from $1,950 2022-09-20
Nuc M15 Laptop Kit Lapbc510 Firmware HIGH 8.8
CVE-2022-40250

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an enviro…

No fix yet
Fix from $1,950 2022-09-20
Debian Linux HIGH 7.5
CVE-2022-40149

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user suppl…

Fix: after 1.4.0
Fix from $1,950 2022-09-16
Xstream HIGH 7.5
CVE-2022-40151

Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an at…

Fix: 1.4.20+
Fix from $1,950 2022-09-16
Xstream HIGH 7.5
CVE-2022-40152EPSS 20%

Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on us…

Fix: 1.4.20 / 5.4.0+
Fix from $1,950 2022-09-16
Cs C6n A0 1c2wfr Firmware CRITICAL 9.8
CVE-2022-2471

Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-C6N-A0-1C2WFR, CS-DB1C-A0-1E2…

Mitigation only
Fix from $2,300 2022-09-15
Chengming 3900 Firmware HIGH 7.8
CVE-2022-31226

Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could potentially exploit this vulnerabi…

Fix: 1.1.0 / 1.1.66+
Fix from $1,950 2022-09-12
Alienware M15 R6 Firmware HIGH 7.8
CVE-2022-26860

Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerability by sending malicious input …

Fix: 1.8.0 / 1.8.2+
Fix from $1,950 2022-09-06
Endpoint Encryption MEDIUM 6.5
CVE-2022-2402

The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting …

Fix: 1.3.2.32 / 5.1.2.26+
Fix from $1,600 2022-09-06
Enterprise Linux HIGH 7.8
CVE-2022-25308

A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi app…

Fix: 1.0.12+
Fix from $1,950 2022-09-06
Debian Linux MEDIUM 6.5
CVE-2022-38749

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …

Fix: 1.31+
Fix from $1,600 2022-09-05
Debian Linux MEDIUM 5.5
CVE-2022-38750

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …

Fix: 1.31+
Fix from $1,600 2022-09-05
Debian Linux MEDIUM 6.5
CVE-2022-38751

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …

Fix: 1.31+
Fix from $1,600 2022-09-05
Snakeyaml MEDIUM 6.5
CVE-2022-38752

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …

Fix: 1.32+
Fix from $1,600 2022-09-05
Scadapro Server HIGH 7.8
CVE-2022-2895

Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based buffer overflow instances whi…

Mitigation only
Fix from $1,950 2022-08-31
Scadapro Server HIGH 7.8
CVE-2022-2896

Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file.

Mitigation only
Fix from $1,950 2022-08-31
Fedora MEDIUM 6.1
CVE-2022-1355

A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiff…

Fix: 4.4.0+
Fix from $1,600 2022-08-31
Cncsoft HIGH 7.8
CVE-2022-1405

CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowing a possible stack-based buf…

Fix: 1.01.32+
Fix from $1,950 2022-08-31
Alpha7 Pc Loader Firmware HIGH 7.8
CVE-2022-1888

Alpha7 PC Loader (All versions) is vulnerable to a stack-based buffer overflow while processing a specifically crafted project file, which may allow …

Mitigation only
Fix from $1,950 2022-08-31
Mds 9506 Firmware HIGH 8.8
CVE-2022-20824

A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent atta…

Mitigation only
Fix from $1,950 2022-08-25
Json\+\+ HIGH 7.5
CVE-2022-23460

Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx json parsing may lead to stack exhaustion in an a…

Mitigation only
Fix from $1,950 2022-08-19
Meeting Connector CRITICAL 9.8
CVE-2022-28750

Zoom On-Premise Meeting Connector Zone Controller (ZC) before version 4.8.20220419.112 fails to properly parse STUN error codes, which can result in …

Fix: 4.8.20220419.112+
Fix from $2,300 2022-08-11
Linkhub Mesh Wifi Ac1200 CRITICAL 9.8
CVE-2022-25996

A stack-based buffer overflow vulnerability exists in the confsrv addTimeGroup functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-…

No fix yet
Fix from $2,300 2022-08-05
Linkhub Mesh Wifi Ac1200 CRITICAL 9.8
CVE-2022-26009

A stack-based buffer overflow vulnerability exists in the confsrv ucloud_set_node_location functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. …

No fix yet
Fix from $2,300 2022-08-05