Vulnerability index

Browse CVEs

2,665 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Linux Kernel CRITICAL 9.8
CVE-2019-10126EPSS 7%

A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.…

Fix: 4.4.186 / 4.9.186+
Fix from $2,300 2019-06-14
Control Fpwin Pro HIGH 7.8
CVE-2019-6530EPSS 7%

Panasonic FPWIN Pro version 7.3.0.0 and prior allows attacker-created project files to be loaded by an authenticated user causing heap-based buffer o…

Fix: after 7.3.0.0
Fix from $1,950 2019-06-07
Linux Kernel HIGH 8.8
CVE-2019-3846EPSS 6%

A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malic…

Fix: 3.16.70 / 4.4.186+
Fix from $1,950 2019-06-03
Galaxy S9 Firmware HIGH 8.8
CVE-2019-6740

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security …

Fix: 2019-01+
Fix from $1,950 2019-06-03
Fedora HIGH 7.8
CVE-2019-5436EPSS 50%

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

Fix: after 7.64.1
Fix from $1,950 2019-05-28
Whatsapp CRITICAL 9.8
CVE-2019-3568 KEVEPSS 39%

A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTCP packets sent to a target ph…

Fix: 2.18.15 / 2.18.348+
Fix from $2,300 2019-05-14
Daviewindy HIGH 7.8
CVE-2019-9135

DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed DIB format file that is mi…

Fix: after 8.98.7
Fix from $1,950 2019-04-25
Daviewindy HIGH 7.8
CVE-2019-9136

DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malformed JPEG2000 format file that …

Fix: after 8.98.7
Fix from $1,950 2019-04-25
Cncsoft Screeneditor HIGH 7.8
CVE-2019-10951

Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow vulnerabilities may be explo…

Fix: after 1.00.88
Fix from $1,950 2019-04-17
Experion Process Knowledge System CRITICAL 9.8
CVE-2014-9187

Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and a…

Mitigation only
Fix from $2,300 2019-03-25
Softcms HIGH 8.8
CVE-2015-6457

Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version…

Fix: after 1.3
Fix from $1,950 2019-03-21
Ultravnc CRITICAL 9.8
CVE-2019-8271EPSS 8%

UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer handler, which can potentially result code ex…

Fix: 1.2.2.3 / 4.8+
Fix from $2,300 2019-03-08
Ultravnc CRITICAL 9.8
CVE-2019-8273EPSS 8%

UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler, which can potentially result…

Fix: 1.2.2.3 / 4.8+
Fix from $2,300 2019-03-08
Ultravnc CRITICAL 9.8
CVE-2019-8274EPSS 8%

UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, which can potentially in resul…

Fix: 1.2.2.3 / 4.8+
Fix from $2,300 2019-03-08
Office Server Document Converter CRITICAL 9.8
CVE-2019-5019

A heap-based overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro R1…

No fix yet
Fix from $2,300 2019-03-07
Ultravnc CRITICAL 9.8
CVE-2019-8258

UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This attack appears to be exploitabl…

Fix: 1.2.2.3 / 4.8+
Fix from $2,300 2019-03-05
Ultravnc CRITICAL 9.8
CVE-2019-8262

UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which results in code execution. Th…

Fix: 1.2.2.3 / 4.8+
Fix from $2,300 2019-03-05
Levistudiou HIGH 7.8
CVE-2019-6539

Several heap-based buffer overflow vulnerabilities in WECON LeviStudioU version 1.8.56 and prior have been identified, which may allow arbitrary code…

Fix: after 1.8.56
Fix from $1,950 2019-02-13
Debian Linux CRITICAL 9.8
CVE-2018-8793EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corrupti…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8797EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8800EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corrupti…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Factorytalk Services Platform HIGH 7.5
CVE-2018-18981

In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to servi…

Fix: after 2.90
Fix from $1,950 2019-01-24
Hhvm CRITICAL 9.8
CVE-2018-6345

The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively large. The internal implement…

Fix: after 3.30.1
Fix from $2,300 2019-01-15
Whatsapp HIGH 7.5
CVE-2018-6344

A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulnerability can be used to cause …

Fix: 2.18.93 / 2.18.172+
Fix from $1,950 2018-12-31
Sinumerik 828d V4.7 Firmware HIGH 8.1
CVE-2018-11457

A vulnerability has been identified in SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINUM…

Fix: after 4.8
Fix from $1,950 2018-12-12
Libiec61850 HIGH 7.5
CVE-2018-19093

An issue has been found in libIEC61850 v1.3. It is a SEGV in ControlObjectClient_setCommandTerminationHandler in client/client_control.c. NOTE: the s…

No fix yet
Fix from $1,950 2018-11-07
Samba HIGH 8.8
CVE-2016-2123EPSS 6%

A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-cont…

Fix: 4.3.13 / 4.4.8+
Fix from $1,950 2018-11-01
Gluster Storage HIGH 8.8
CVE-2018-14653

The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_…

Fix: after 4.1.4
Fix from $1,950 2018-10-31
Curl CRITICAL 9.8
CVE-2018-16839EPSS 6%

Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service.

Fix: after 7.61.1
Fix from $2,300 2018-10-31
Proessentials HIGH 7.6
CVE-2017-7908

A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML f…

Fix: after 5
Fix from $1,950 2018-10-02