Vulnerability index

Browse CVEs

3,570 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Stack-based Buffer OverflowCWE-121 × clear
Uftpd HIGH 8.8
CVE-2020-5204

In uftpd before 2.11, there is a buffer overflow vulnerability in handle_PORT in ftpcmd.c that is caused by a buffer that is 16 bytes large being fil…

Fix: 2.11+
Fix from $1,950 2020-01-06
Tigervnc HIGH 7.2
CVE-2019-15695

TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readSetCursor. This vulnerability …

Fix: 1.10.1+
Fix from $1,950 2019-12-26
Plc Editor HIGH 7.8
CVE-2019-18236

Multiple buffer overflow vulnerabilities exist when the PLC Editor Version 1.3.5_20190129 processes project files. An attacker could use a specially …

Mitigation only
Fix from $1,950 2019-12-23
Sma 100 Firmware CRITICAL 9.8
CVE-2019-7482EPSS 9%

Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability im…

Fix: after 9.0.0.3
Fix from $2,300 2019-12-19
Diaganywhere CRITICAL 9.8
CVE-2019-18257

In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist in the file transfer service…

Fix: after 3.07.11
Fix from $2,300 2019-12-17
Webaccess CRITICAL 9.8
CVE-2019-3951

Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service (memory corruption) d…

Fix: 8.4.3+
Fix from $2,300 2019-12-12
Sppa T3000 Ms3000 Migration Server HIGH 7.5
CVE-2019-18310

A vulnerability has been identified in SPPA-T3000 MS3000 Migration Server (All versions). An attacker with network access to the MS3000 Server could …

Mitigation only
Fix from $1,950 2019-12-12
Enterprise Linux CRITICAL 9.8
CVE-2019-19333

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits…

Patch available
Fix from $2,300 2019-12-06
Enterprise Linux CRITICAL 9.8
CVE-2019-19334

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "iden…

Patch available
Fix from $2,300 2019-12-06
Linux Kernel CRITICAL 9.8
CVE-2019-14897

A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denia…

Fix: 3.16.83 / 4.4.212+
Fix from $2,300 2019-11-29
Whatsapp HIGH 7.8
CVE-2019-11931

A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user. The issue was present in par…

Fix: 2.19.100 / 2.19.104+
Fix from $1,950 2019-11-14
Turbovnc CRITICAL 9.8
CVE-2019-15683EPSS 19%

TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a536136e. This could possibly re…

Fix: 2.2.3+
Fix from $2,300 2019-10-29
Phantompdf HIGH 8.8
CVE-2019-17145EPSS 5%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is r…

Mitigation only
Fix from $1,950 2019-10-25
Webaccess HIGH 8.8
CVE-2019-13556

In WebAccess versions 8.4.1 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of proper validation of the length o…

Fix: after 8.4.1
Fix from $1,950 2019-09-18
Control For Beaglebone CRITICAL 9.8
CVE-2019-13548EPSS 6%

CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack…

Fix: 3.5.12.80 / 3.5.14.10+
Fix from $2,300 2019-09-13
Tpeditor HIGH 7.8
CVE-2019-13540

Delta Electronics TPEditor, Versions 1.94 and prior. Multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially cr…

Fix: after 1.94
Fix from $1,950 2019-09-11
Ez Touch Editor HIGH 7.8
CVE-2019-13518

An attacker could use a specially crafted project file to overflow the buffer and execute code under the privileges of the EZ Touch Editor Versions 2…

Fix: after 2.1.0
Fix from $1,950 2019-09-04
Cloud Explorer HIGH 7.5
CVE-2019-13156

NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data fr…

Mitigation only
Fix from $1,950 2019-09-03
Aspose.words HIGH 8.8
CVE-2019-5041

An exploitable Stack Based Buffer Overflow vulnerability exists in the EnumMetaInfo function of Aspose Aspose.Words library, version 18.11.0.0. A spe…

Mitigation only
Fix from $1,950 2019-08-21
Openweave Core HIGH 8.8
CVE-2019-5038

An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based…

No fix yet
Fix from $1,950 2019-08-20
Alpha5 Smart Loader Firmware HIGH 7.8
CVE-2019-13520

Multiple buffer overflow issues have been identified in Alpha5 Smart Loader: All versions prior to 4.2. An attacker could use specially crafted proje…

Fix: 4.2+
Fix from $1,950 2019-08-20
Windows 10 HIGH 7.3
CVE-2019-1185

An elevation of privilege vulnerability exists due to a stack corruption in Windows Subsystem for Linux. An attacker who successfully exploited the v…

Patch available
Fix from $1,950 2019-08-14
Liblouis HIGH 7.8
CVE-2014-8184

A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker c…

Fix: 2.5.4+
Fix from $1,950 2019-08-02
Energyplus MEDIUM 5.5
CVE-2019-10974

NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from being overwritten with arbitr…

Fix: after 8.6.0
Fix from $1,600 2019-07-26
Debian Linux HIGH 7.8
CVE-2019-0053

Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exp…

No fix yet
Fix from $1,950 2019-07-11
Redis HIGH 7.2
CVE-2019-10193EPSS 24%

A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before …

Fix: 3.2.13 / 4.0.14+
Fix from $1,950 2019-07-11
PostgreSQL HIGH 8.8
CVE-2019-10164

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overfl…

Fix: 10.9 / 11.4+
Fix from $1,950 2019-06-26
Whatsapp CRITICAL 9.8
CVE-2018-6339

When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data being passed in. An off-by-one e…

Fix: 2.18.150 / 2.18.295+
Fix from $2,300 2019-06-14
Whatsapp CRITICAL 9.8
CVE-2018-6349

When receiving calls using WhatsApp for Android, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow. This …

Fix: 2.18.132 / 2.18.248+
Fix from $2,300 2019-06-14
Whatsapp CRITICAL 9.8
CVE-2018-20655

When receiving calls using WhatsApp for iOS, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow. This issu…

Fix: 2.18.90.24+
Fix from $2,300 2019-06-14