Vulnerability index

Browse CVEs

2,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Unclassified MEDIUM 6.8
CVE-2024-0145

NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a heap-based buffer overflow issue by means of a specially crafted JPE…

Mitigation only
Fix from $1,600 2025-02-12
Mintty HIGH 8.8
CVE-2025-1052

Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Fix: 3.7.5+
Fix from $1,950 2025-02-11
Pdf Xchange Editor HIGH 8.8
CVE-2025-0903

PDF-XChange Editor RTF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exe…

Fix: 10.4.2.390+
Fix from $1,950 2025-02-11
Windows 10 1607 HIGH 7.8
CVE-2025-21418 KEV

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Fix: 10.0.10240.20915 / 10.0.17763.6893+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 8.8
CVE-2025-21407

Windows Telephony Service Remote Code Execution Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Windows Server 2008 HIGH 8.8
CVE-2025-21410

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Fix: 10.0.14393.7785 / 10.0.17763.6893+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 7.0
CVE-2025-21414

Windows Core Messaging Elevation of Privileges Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
365 Apps HIGH 7.8
CVE-2025-21390

Microsoft Excel Remote Code Execution Vulnerability

Fix: 16.0.10416.20058+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 8.1
CVE-2025-21376EPSS 9%

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 8.8
CVE-2025-21368

Microsoft Digest Authentication Remote Code Execution Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 8.8
CVE-2025-21369

Microsoft Digest Authentication Remote Code Execution Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 8.8
CVE-2025-21371

Windows Telephony Service Remote Code Execution Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 7.8
CVE-2025-21375

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 8.8
CVE-2025-21200

Windows Telephony Service Remote Code Execution Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Windows Server 2008 HIGH 8.8
CVE-2025-21208

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Fix: 10.0.14393.7785 / 10.0.17763.6893+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 7.0
CVE-2025-21184

Windows Core Messaging Elevation of Privileges Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Windows 10 1507 HIGH 8.8
CVE-2025-21190

Windows Telephony Service Remote Code Execution Vulnerability

Fix: 10.0.10240.20915 / 10.0.14393.7785+
Fix from $1,950 2025-02-11
Indesign HIGH 7.8
CVE-2025-21123

InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code…

Fix: 19.5.2+
Fix from $1,950 2025-02-11
Binutils MEDIUM 5.0
CVE-2025-1176

A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.…

Patch available
Fix from $1,600 2025-02-11
Cncsoft G2 HIGH 7.8
CVE-2025-22880

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. If …

Fix: 2.1.0.20+
Fix from $1,950 2025-02-07
Cobalt HIGH 7.8
CVE-2023-40222

In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of user-supplied data when parsi…

Fix: 12.4.1204.200+
Fix from $1,950 2025-02-04
Bento4 MEDIUM 5.9
CVE-2025-0870

A vulnerability was found in Axiomatic Bento4 up to 1.6.0-641. It has been rated as critical. Affected by this issue is the function AP4_DataBuffer::…

Fix: after 1.6.0-641
Fix from $1,600 2025-01-30
Bento4 MEDIUM 6.5
CVE-2025-0753

A vulnerability classified as critical was found in Axiomatic Bento4 up to 1.6.0. This vulnerability affects the function AP4_StdcFileByteStream::Rea…

Fix: after 1.6.0
Fix from $1,600 2025-01-27
Bento4 MEDIUM 6.5
CVE-2025-0751

A vulnerability classified as critical has been found in Axiomatic Bento4 up to 1.6.0. This affects the function AP4_BitReader::ReadBits of the compo…

Fix: after 1.6.0
Fix from $1,600 2025-01-27
Winet S Firmware CRITICAL 9.8
CVE-2024-50698

SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of the MQTT message content.

Fix: 200.001.00.p027+
Fix from $2,300 2025-01-24
Unclassified HIGH 8.8
CVE-2019-15690

LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() function in libvncclient/cursor.c.…

Mitigation only
Fix from $1,950 2025-01-24
Openimageio CRITICAL 9.8
CVE-2024-55192

OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*).

No fix yet
Fix from $2,300 2025-01-23
Chrome HIGH 8.2
CVE-2025-0611

Object corruption in V8 in Google Chrome prior to 132.0.6834.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 132.0.6834.110+
Fix from $1,950 2025-01-22
Secure Endpoint HIGH 7.5
CVE-2025-20128

A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a …

Fix: 1.0.8 / 1.4.2+
Fix from $1,950 2025-01-22
Unclassified HIGH 8.8
CVE-2023-50739

A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) in various Lexmark devices. The vulnerability can be leve…

Mitigation only
Fix from $1,950 2025-01-18