Vulnerability index

Browse CVEs

3,570 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Stack-based Buffer OverflowCWE-121 × clear
Sigma Lite Firmware CRITICAL 9.8
CVE-2023-33218

The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. This could potentially lead to a Remote …

Fix: 1.2.7 / 2.12.2+
Fix from $2,300 2023-12-15
Sigma Lite Firmware CRITICAL 9.8
CVE-2023-33219

The handler of the retrofit validation command doesn't properly check the boundaries when performing certain validation operations. This allows a st…

Fix: 1.2.7 / 2.12.2+
Fix from $2,300 2023-12-15
Sigma Lite Firmware CRITICAL 9.8
CVE-2023-33220

During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some attributes to check. This allows a sta…

Fix: 1.2.7 / 2.12.2+
Fix from $2,300 2023-12-15
Jq MEDIUM 5.5
CVE-2023-50268

jq is a command-line JSON processor. Version 1.7 is vulnerable to stack-based buffer overflow in builds using decNumber. Version 1.7.1 contains a pat…

Patch available
Fix from $1,600 2023-12-13
Windows 10 1507 HIGH 8.8
CVE-2023-36006

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

Fix: 10.0.10240.20345 / 10.0.14393.6529+
Fix from $1,950 2023-12-12
Windows 11 21h2 HIGH 8.8
CVE-2023-35634

Windows Bluetooth Driver Remote Code Execution Vulnerability

Fix: 10.0.22000.2652 / 10.0.22621.2861+
Fix from $1,950 2023-12-12
Ax12 Firmware CRITICAL 9.8
CVE-2023-49424

Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

No fix yet
Fix from $2,300 2023-12-07
Dopsoft HIGH 7.8
CVE-2023-5944

Delta Electronics DOPSoft is vulnerable to a stack-based buffer overflow, which may allow for arbitrary code execution if an attacker can lead a legi…

Mitigation only
Fix from $1,950 2023-12-04
Aleos MEDIUM 5.5
CVE-2023-40465

Several versions of ALEOS, including ALEOS 4.16.0, include an opensource third-party component which can be exploited from the local area netwo…

Fix: after 4.16.0
Fix from $1,600 2023-12-04
Dm5500 Firmware CRITICAL 9.8
CVE-2023-44305

Dell DM5500 5.14.0.0, contains a Stack-based Buffer Overflow Vulnerability in the appliance. An unauthenticated remote attacker may exploit this vuln…

Fix: after 5.14.0.0
Fix from $2,300 2023-12-04
Tinydir CRITICAL 9.8
CVE-2023-49287

TinyDir is a lightweight C directory and file reader. Buffer overflows in the `tinydir_file_open()` function. This vulnerability has been patched in …

Fix: 1.2.6+
Fix from $2,300 2023-12-04
Ac10 Firmware CRITICAL 9.8
CVE-2023-45481

Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter in the function SetFirewallC…

No fix yet
Fix from $2,300 2023-11-29
Tellus Lite V Simulator HIGH 7.8
CVE-2023-35127

Stack-based buffer overflow may occur when Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file.

Fix: 4.0.19.0+
Fix from $1,950 2023-11-22
Zephyr CRITICAL 9.8
CVE-2023-5055

Possible variant of CVE-2021-3434 in function le_ecred_reconf_req.

Fix: after 3.4.0
Fix from $2,300 2023-11-21
Cf7500 Firmware CRITICAL 9.8
CVE-2023-4249EPSS 10%

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 has a …

Mitigation only
Fix from $2,300 2023-11-08
Cf7500 Firmware CRITICAL 9.8
CVE-2023-45225

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras  with firmware version M2.1.6.05 are vul…

Mitigation only
Fix from $2,300 2023-11-08
Cf7500 Firmware CRITICAL 9.8
CVE-2023-43755

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vu…

Mitigation only
Fix from $2,300 2023-11-08
Cf7500 Firmware CRITICAL 9.8
CVE-2023-39435

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vuln…

Mitigation only
Fix from $2,300 2023-11-08
Cf7500 Firmware CRITICAL 9.8
CVE-2023-3959EPSS 40%

Zavio CF7500, CF7300, CF7201, CF7501, CB3211, CB3212, CB5220, CB6231, B8520, B8220, and CD321 IP Cameras with firmware version M2.1.6.05 are vul…

Mitigation only
Fix from $2,300 2023-11-08
Insydeh2o CRITICAL 9.8
CVE-2023-39281

A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrar…

Mitigation only
Fix from $2,300 2023-11-01
Elasticsearch HIGH 7.5
CVE-2023-31419EPSS 61%

A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimat…

Fix: after 8.9.0
Fix from $1,950 2023-10-26
X2000r Firmware CRITICAL 9.8
CVE-2023-46552

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMultiAP.

No fix yet
Fix from $2,300 2023-10-25
X2000r Firmware CRITICAL 9.8
CVE-2023-46553

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formParentControl.

No fix yet
Fix from $2,300 2023-10-25
X2000r Firmware CRITICAL 9.8
CVE-2023-46559

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIPv6Addr.

No fix yet
Fix from $2,300 2023-10-25
X2000r Firmware CRITICAL 9.8
CVE-2023-46560

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.

No fix yet
Fix from $2,300 2023-10-25
X2000r Firmware CRITICAL 9.8
CVE-2023-46562

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.

No fix yet
Fix from $2,300 2023-10-25
X2000r Firmware CRITICAL 9.8
CVE-2023-46563

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.

No fix yet
Fix from $2,300 2023-10-25
X2000r Firmware CRITICAL 9.8
CVE-2023-46564

TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.

No fix yet
Fix from $2,300 2023-10-25
Cmt Fhd Firmware CRITICAL 9.8
CVE-2023-38584

In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker t…

Fix: 20210206 / 20210212+
Fix from $2,300 2023-10-19
Cmt Fhd Firmware CRITICAL 9.8
CVE-2023-43492

In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to h…

Fix: 20210206 / 20210212+
Fix from $2,300 2023-10-19