Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
macOS HIGH 7.8
CVE-2023-42902

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously c…

Fix: 14.2+
Fix from $1,950 2023-12-12
macOS HIGH 7.8
CVE-2023-42903

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously c…

Fix: 14.2+
Fix from $1,950 2023-12-12
A7000r Firmware CRITICAL 9.8
CVE-2023-49417

TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg.

No fix yet
Fix from $2,300 2023-12-11
A7000r Firmware CRITICAL 9.8
CVE-2023-49418

TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules.

No fix yet
Fix from $2,300 2023-12-11
Jq HIGH 7.5
CVE-2023-49355

decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same…

Patch available
Fix from $1,950 2023-12-11
Gpac CRITICAL 9.8
CVE-2023-46932

Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitrary code and cause a denial of…

No fix yet
Fix from $2,300 2023-12-09
Informix Dynamic Server MEDIUM 5.5
CVE-2023-28526

IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a…

Mitigation only
Fix from $1,600 2023-12-09
Informix Dynamic Server MEDIUM 5.5
CVE-2023-28527

IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local…

Mitigation only
Fix from $1,600 2023-12-09
Informix Dynamic Server HIGH 7.8
CVE-2023-28523

IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an…

Mitigation only
Fix from $1,950 2023-12-09
Nuxt Api Party HIGH 7.5
CVE-2023-49800

`nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no f…

Fix: after 0.21.3
Fix from $1,950 2023-12-09
Android HIGH 7.8
CVE-2023-48421

In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/pixel/pixel_gpu_slc.c, there is a possible out of …

Mitigation only
Fix from $1,950 2023-12-08
Android CRITICAL 9.8
CVE-2023-48423

In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executi…

Mitigation only
Fix from $2,300 2023-12-08
Android HIGH 7.5
CVE-2023-48403

In sms_DecodeCodedTpMsg of sms_PduCodec.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote informatio…

Mitigation only
Fix from $1,950 2023-12-08
Rbr750 Firmware CRITICAL 9.8
CVE-2023-49007EPSS 9%

In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd.

Fix: 7.2.6.21+
Fix from $2,300 2023-12-08
Libde265 HIGH 8.8
CVE-2023-49465

Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc.

Patch available
Fix from $1,950 2023-12-07
Libde265 HIGH 8.8
CVE-2023-49467

Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at mo…

Patch available
Fix from $1,950 2023-12-07
Libde265 HIGH 8.8
CVE-2023-49468

Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc.

Patch available
Fix from $1,950 2023-12-07
W30e Firmware CRITICAL 9.8
CVE-2023-49404

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.

No fix yet
Fix from $2,300 2023-12-07
W30e Firmware CRITICAL 9.8
CVE-2023-49405

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.

No fix yet
Fix from $2,300 2023-12-07
Ax3 Firmware CRITICAL 9.8
CVE-2023-49408

Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.

No fix yet
Fix from $2,300 2023-12-07
W30e Firmware CRITICAL 9.8
CVE-2023-49411

Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.

No fix yet
Fix from $2,300 2023-12-07
W30e Firmware CRITICAL 9.8
CVE-2023-49402

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.

No fix yet
Fix from $2,300 2023-12-07
W30e Firmware CRITICAL 9.8
CVE-2023-49403

Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.

No fix yet
Fix from $2,300 2023-12-07
W30e Firmware CRITICAL 9.8
CVE-2023-49410

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.

No fix yet
Fix from $2,300 2023-12-07
W30e Firmware CRITICAL 9.8
CVE-2023-49999

Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.

No fix yet
Fix from $2,300 2023-12-07
W30e Firmware CRITICAL 9.8
CVE-2023-50000

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.

No fix yet
Fix from $2,300 2023-12-07
W30e Firmware CRITICAL 9.8
CVE-2023-50001

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.

No fix yet
Fix from $2,300 2023-12-07
W30e Firmware CRITICAL 9.8
CVE-2023-50002

Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.

No fix yet
Fix from $2,300 2023-12-07
Ax9 Firmware CRITICAL 9.8
CVE-2023-49430

Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.

No fix yet
Fix from $2,300 2023-12-07
Ax9 Firmware CRITICAL 9.8
CVE-2023-49432

Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.

No fix yet
Fix from $2,300 2023-12-07