Vulnerability index

Browse CVEs

3,570 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Stack-based Buffer OverflowCWE-121 × clear
Pc Worx HIGH 7.8
CVE-2020-12498

mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. M…

Fix: 1.87+
Fix from $1,950 2020-07-01
Xrdp HIGH 7.8
CVE-2020-4044

The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman p…

Fix: 0.9.13.1+
Fix from $1,950 2020-06-30
Webaccess CRITICAL 9.8
CVE-2020-12019

WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

Fix: after 8.4.4
Fix from $2,300 2020-06-15
Pan Os HIGH 7.2
CVE-2020-2027

A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processe…

Fix: 8.1.13 / 9.0.7+
Fix from $1,950 2020-06-10
Pan Os HIGH 8.8
CVE-2020-2006

A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arb…

Fix: after 8.1.13
Fix from $1,950 2020-05-13
Webaccess CRITICAL 9.8
CVE-2020-12002EPSS 9%

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of prop…

Fix: after 8.4.4
Fix from $2,300 2020-05-08
Abbs Software Audio Media Player HIGH 7.8
CVE-2019-5621

ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow.

No fix yet
Fix from $1,950 2020-04-29
Wav To Mp3 HIGH 7.8
CVE-2019-5618

A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow.

No fix yet
Fix from $1,950 2020-04-29
Aasync CRITICAL 9.8
CVE-2019-5619

AASync.com AASync version 2.2.1.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow.

No fix yet
Fix from $2,300 2020-04-29
Scada Data Gateway HIGH 7.5
CVE-2020-10615

Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers cause a denial-of-service conditi…

Fix: after 4.0.122
Fix from $1,950 2020-04-15
Dnp3 Source Code Library CRITICAL 9.8
CVE-2020-6996

Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source code libraries are affected:3…

Fix: after 3.25.01
Fix from $2,300 2020-04-15
Hmisoft Vu3 Firmware HIGH 7.8
CVE-2020-10639

Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially…

Fix: after 3.00.23
Fix from $1,950 2020-04-15
Pan Os HIGH 7.2
CVE-2020-1990

A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to upload a corrupted PAN-OS co…

Fix: 8.1.13 / 9.0.7+
Fix from $1,950 2020-04-08
1080 Lite 8ch Firmware HIGH 8.8
CVE-2020-5735 KEVEPSS 36%

Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to cra…

Mitigation only
Fix from $1,950 2020-04-08
Vbase Editor CRITICAL 9.8
CVE-2020-10599

VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overfl…

Mitigation only
Fix from $2,300 2020-04-03
PHP HIGH 8.8
CVE-2020-7065

In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could …

Fix: 5.19.0 / 7.3.16+
Fix from $1,950 2020-04-01
Idrac7 Firmware CRITICAL 9.8
CVE-2020-5344

Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unaut…

Fix: 2.65.65.65 / 2.70.70.70+
Fix from $2,300 2020-03-31
Webaccess HIGH 8.8
CVE-2020-10607

In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper validation of the length of …

Fix: after 8.4.2
Fix from $1,950 2020-03-27
Ac1750 Firmware CRITICAL 9.8
CVE-2020-10881EPSS 11%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route…

Mitigation only
Fix from $2,300 2020-03-25
Eds G516e Firmware CRITICAL 9.8
CVE-2020-7007

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the attacker may execute arbitrary codes or target the device, causing it to go out of servi…

Fix: after 5.2
Fix from $2,300 2020-03-24
Pt 7528 24tx Hv Firmware CRITICAL 9.8
CVE-2020-6989

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, a buffer overflow in the web server allows …

Fix: after 4.0
Fix from $2,300 2020-03-24
Cncsoft Screeneditor HIGH 7.8
CVE-2020-7002

Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be exploited when a valid user opens …

Fix: after 1.00.96
Fix from $1,950 2020-03-18
Awk 3131a Firmware HIGH 8.8
CVE-2019-5153

An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1…

No fix yet
Fix from $1,950 2020-02-25
Android HIGH 8.0
CVE-2020-8860

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), …

Mitigation only
Fix from $1,950 2020-02-22
Messagepack MEDIUM 6.5
CVE-2020-5234

MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions …

Fix: 1.9.3 / 2.1.80+
Fix from $1,600 2020-01-31
Wemo Insight Switch Firmware HIGH 7.8
CVE-2019-17094

A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain co…

Fix: 2.00.11396+
Fix from $1,950 2020-01-27
Junos HIGH 8.8
CVE-2020-1605

When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured…

Mitigation only
Fix from $1,950 2020-01-15
Junos HIGH 8.8
CVE-2020-1609

When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured…

Mitigation only
Fix from $1,950 2020-01-15
Iec870ip Firmware HIGH 7.5
CVE-2019-13537

The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffer overflow vulnerability that…

Fix: after 4.14.02
Fix from $1,950 2020-01-14
Dcs 935l Firmware CRITICAL 9.8
CVE-2019-17146EPSS 10%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not re…

Fix: after 1.12.101
Fix from $2,300 2020-01-07