Vulnerability index

Browse CVEs

2,663 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Rv042 Firmware MEDIUM 6.8
CVE-2024-20522

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, A…

Mitigation only
Fix from $1,600 2024-10-02
Rv042 Firmware MEDIUM 6.8
CVE-2024-20516

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, A…

Mitigation only
Fix from $1,600 2024-10-02
Rv042 Firmware MEDIUM 6.8
CVE-2024-20517

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, A…

Mitigation only
Fix from $1,600 2024-10-02
Cute Png HIGH 7.8
CVE-2024-46264

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.

No fix yet
Fix from $1,950 2024-10-01
Navisworks HIGH 7.8
CVE-2024-7673

A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can …

Mitigation only
Fix from $1,950 2024-09-30
Navisworks HIGH 7.8
CVE-2024-7674

A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor ca…

Mitigation only
Fix from $1,950 2024-09-30
Giflib MEDIUM 6.5
CVE-2024-45993

Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.

Mitigation only
Fix from $1,600 2024-09-30
Unclassified MEDIUM 5.9
CVE-2024-38796

EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network.…

Mitigation only
Fix from $1,600 2024-09-27
Sqlite Vec MEDIUM 5.5
CVE-2024-46488

sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a De…

No fix yet
Fix from $1,600 2024-09-25
Unified Threat Defense Snort Intrusion Prevention System Engine MEDIUM 6.5
CVE-2024-20508

A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthe…

Mitigation only
Fix from $1,600 2024-09-25
Unclassified HIGH 8.0
CVE-2024-46461

VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafte…

Mitigation only
Fix from $1,950 2024-09-25
Chrome HIGH 7.8
CVE-2024-7018

Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PD…

Fix: 124.0.6367.78+
Fix from $1,950 2024-09-23
Assimp HIGH 8.4
CVE-2024-45679

Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially…

Fix: 5.4.3+
Fix from $1,950 2024-09-18
Mf296r Firmware MEDIUM 6.5
CVE-2022-39068

There is a buffer overflow vulnerability in ZTE MF296R. Due to insufficient validation of the SMS parameter length, an authenticated attacker could u…

Mitigation only
Fix from $1,600 2024-09-18
Chrome HIGH 8.8
CVE-2024-8905

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a cr…

Fix: 129.0.6668.58+
Fix from $1,950 2024-09-17
Micropython HIGH 7.5
CVE-2024-8946

A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c …

Patch available
Fix from $1,950 2024-09-17
Micropython HIGH 7.5
CVE-2024-8948

A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/ob…

Patch available
Fix from $1,950 2024-09-17
Cloud Foundation CRITICAL 9.8
CVE-2024-38812 KEVEPSS 55%

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCen…

Fix: 5.2+
Fix from $2,300 2024-09-17
Zephyr MEDIUM 6.5
CVE-2024-6259

BT: HCI: adv_ext_report Improper discarding in adv_ext_report

Fix: after 3.6.0
Fix from $1,600 2024-09-13
Zephyr MEDIUM 6.5
CVE-2024-6135

BT:Classic: Multiple missing buf length checks

Fix: after 3.6.0
Fix from $1,600 2024-09-13
Zephyr MEDIUM 6.5
CVE-2024-6258

BT: Missing length checks of net_buf in rfcomm_handle_data

Fix: 3.6.0+
Fix from $1,600 2024-09-13
Photoshop HIGH 7.8
CVE-2024-43756

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code e…

Fix: 24.7.5 / 25.12+
Fix from $1,950 2024-09-13
After Effects HIGH 7.8
CVE-2024-39380

After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execut…

Fix: 23.6.9 / 24.6+
Fix from $1,950 2024-09-13
Chrome HIGH 8.8
CVE-2024-8636

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Fix: 128.0.6613.137+
Fix from $1,950 2024-09-11
Windows 10 1507 HIGH 7.8
CVE-2024-38242

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.20766 / 10.0.14393.7336+
Fix from $1,950 2024-09-10
Windows 10 1507 HIGH 7.8
CVE-2024-38237

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.20766 / 10.0.14393.7336+
Fix from $1,950 2024-09-10
Windows 10 1507 HIGH 7.8
CVE-2024-38238

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.20766 / 10.0.14393.7336+
Fix from $1,950 2024-09-10
Windows 10 1809 HIGH 8.1
CVE-2024-38045

Windows TCP/IP Remote Code Execution Vulnerability

Fix: 10.0.17763.6293 / 10.0.19044.4894+
Fix from $1,950 2024-09-10
Sql 2016 Azure Connect Feature Pack HIGH 8.8
CVE-2024-37335

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Fix: 13.0.6441.1 / 14.0.2060.1+
Fix from $1,950 2024-09-10
Sql 2016 Azure Connect Feature Pack HIGH 8.8
CVE-2024-26191

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Fix: 13.0.6441.1 / 14.0.2060.1+
Fix from $1,950 2024-09-10