Vulnerability index

Browse CVEs

3,570 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Stack-based Buffer OverflowCWE-121 × clear
HIGH 7.8 CVE-2020-12498 mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. M… Pc Worx 1.87+ Fix from $1,9502020-07-01 HIGH 7.8 CVE-2020-4044 The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman p… Xrdp 0.9.13.1+ Fix from $1,9502020-06-30 CRITICAL 9.8 CVE-2020-12019 WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code. Webaccess after 8.4.4 Fix from $2,3002020-06-15 HIGH 7.2 CVE-2020-2027 A buffer overflow vulnerability in the authd component of the PAN-OS management server allows authenticated administrators to disrupt system processe… Pan Os 8.1.13 / 9.0.7+ Fix from $1,9502020-06-10 HIGH 8.8 CVE-2020-2006 A stack-based buffer overflow vulnerability in the management server component of PAN-OS that allows an authenticated user to potentially execute arb… Pan Os after 8.1.13 Fix from $1,9502020-05-13 CRITICAL 9.8 CVE-2020-12002EPSS 9% Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of prop… Webaccess after 8.4.4 Fix from $2,3002020-05-08 HIGH 7.8 CVE-2019-5621 ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow. Abbs Software Audio Media Player No fix yet Fix from $1,9502020-04-29 HIGH 7.8 CVE-2019-5618 A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow. Wav To Mp3 No fix yet Fix from $1,9502020-04-29 CRITICAL 9.8 CVE-2019-5619 AASync.com AASync version 2.2.1.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow. Aasync No fix yet Fix from $2,3002020-04-29 HIGH 7.5 CVE-2020-10615 Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers cause a denial-of-service conditi… Scada Data Gateway after 4.0.122 Fix from $1,9502020-04-15 CRITICAL 9.8 CVE-2020-6996 Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source code libraries are affected:3… Dnp3 Source Code Library after 3.25.01 Fix from $2,3002020-04-15 HIGH 7.8 CVE-2020-10639 Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially… Hmisoft Vu3 Firmware after 3.00.23 Fix from $1,9502020-04-15 HIGH 7.2 CVE-2020-1990 A stack-based buffer overflow vulnerability in the management server component of PAN-OS allows an authenticated user to upload a corrupted PAN-OS co… Pan Os 8.1.13 / 9.0.7+ Fix from $1,9502020-04-08 HIGH 8.8 CVE-2020-5735 KEVEPSS 36% Amcrest cameras and NVR are vulnerable to a stack-based buffer overflow over port 37777. An authenticated remote attacker can abuse this issue to cra… 1080 Lite 8ch Firmware Mitigation only Fix from $1,9502020-04-08 CRITICAL 9.8 CVE-2020-10599 VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overfl… Vbase Editor Mitigation only Fix from $2,3002020-04-03 HIGH 8.8 CVE-2020-7065 In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could … PHP 5.19.0 / 7.3.16+ Fix from $1,9502020-04-01 CRITICAL 9.8 CVE-2020-5344 Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unaut… Idrac7 Firmware 2.65.65.65 / 2.70.70.70+ Fix from $2,3002020-03-31 HIGH 8.8 CVE-2020-10607 In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper validation of the length of … Webaccess after 8.4.2 Fix from $1,9502020-03-27 CRITICAL 9.8 CVE-2020-10881EPSS 11% This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 route… Ac1750 Firmware Mitigation only Fix from $2,3002020-03-25 CRITICAL 9.8 CVE-2020-7007 In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the attacker may execute arbitrary codes or target the device, causing it to go out of servi… Eds G516e Firmware after 5.2 Fix from $2,3002020-03-24 CRITICAL 9.8 CVE-2020-6989 In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, a buffer overflow in the web server allows … Pt 7528 24tx Hv Firmware after 4.0 Fix from $2,3002020-03-24 HIGH 7.8 CVE-2020-7002 Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be exploited when a valid user opens … Cncsoft Screeneditor after 1.00.96 Fix from $1,9502020-03-18 HIGH 8.8 CVE-2019-5153 An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1… Awk 3131a Firmware No fix yet Fix from $1,9502020-02-25 HIGH 8.0 CVE-2020-8860 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), … Android Mitigation only Fix from $1,9502020-02-22 MEDIUM 6.5 CVE-2020-5234 MessagePack for C# and Unity before version 1.9.11 and 2.1.90 has a vulnerability where untrusted data can lead to DoS attack due to hash collisions … Messagepack 1.9.3 / 2.1.80+ Fix from $1,6002020-01-31 HIGH 7.8 CVE-2019-17094 A Stack-based Buffer Overflow vulnerability in libbelkin_api.so component of Belkin WeMo Insight Switch firmware allows a local attacker to obtain co… Wemo Insight Switch Firmware 2.00.11396+ Fix from $1,9502020-01-27 HIGH 8.8 CVE-2020-1605 When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured… Junos Mitigation only Fix from $1,9502020-01-15 HIGH 8.8 CVE-2020-1609 When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured… Junos Mitigation only Fix from $1,9502020-01-15 HIGH 7.5 CVE-2019-13537 The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffer overflow vulnerability that… Iec870ip Firmware after 4.14.02 Fix from $1,9502020-01-14 CRITICAL 9.8 CVE-2019-17146EPSS 10% This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not re… Dcs 935l Firmware after 1.12.101 Fix from $2,3002020-01-07