Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Ac10 Firmware CRITICAL 9.8
CVE-2023-45482

Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_…

No fix yet
Fix from $2,300 2023-11-29
Ac10 Firmware CRITICAL 9.8
CVE-2023-45483

Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in the function compare_parentcont…

No fix yet
Fix from $2,300 2023-11-29
Ac10 Firmware CRITICAL 9.8
CVE-2023-45484

Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiG…

No fix yet
Fix from $2,300 2023-11-29
Busybox MEDIUM 5.5
CVE-2023-42366

A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159.

No fix yet
Fix from $1,600 2023-11-27
Ax1803 Firmware CRITICAL 9.8
CVE-2023-49044

Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form…

No fix yet
Fix from $2,300 2023-11-27
Ax1803 Firmware CRITICAL 9.8
CVE-2023-49042

Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the sche…

No fix yet
Fix from $2,300 2023-11-27
Ax1803 Firmware HIGH 7.5
CVE-2023-49047

Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName.

No fix yet
Fix from $1,950 2023-11-27
Ax1803 Firmware CRITICAL 9.8
CVE-2023-49043EPSS 13%

Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the fun…

No fix yet
Fix from $2,300 2023-11-27
Ax1803 Firmware CRITICAL 9.8
CVE-2023-49046

Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function f…

No fix yet
Fix from $2,300 2023-11-27
Clickhouse HIGH 7.5
CVE-2022-44010

An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on po…

Fix: 22.3.12.19 / 22.6.6.16+
Fix from $1,950 2023-11-23
Clickhouse MEDIUM 6.5
CVE-2022-44011

An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow an…

Fix: 22.3.12.19 / 22.6.6.16+
Fix from $1,600 2023-11-23
Autocad CRITICAL 9.8
CVE-2023-29074

A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor …

Fix: 2023.1.4 / 2024.1+
Fix from $2,300 2023-11-23
Autocad CRITICAL 9.8
CVE-2023-29075

A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can …

Fix: 2023.1.4 / 2024.1+
Fix from $2,300 2023-11-23
Autocad HIGH 7.8
CVE-2023-41140

A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious acto…

Fix: 2023.1.4 / 2024.1+
Fix from $1,950 2023-11-23
Autocad CRITICAL 9.8
CVE-2023-29073

A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious ac…

Fix: 2023.1.4 / 2024.1+
Fix from $2,300 2023-11-23
Webassembly Micro Runtime HIGH 7.5
CVE-2023-48105

An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service v…

Patch available
Fix from $1,950 2023-11-22
Minizip Ng HIGH 8.8
CVE-2023-48107

Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_has_slash …

Patch available
Fix from $1,950 2023-11-22
Minizip Ng HIGH 8.8
CVE-2023-48106

Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_resolve fu…

Patch available
Fix from $1,950 2023-11-22
Radare2 HIGH 7.5
CVE-2023-47016

radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h.

Fix: 5.9.0+
Fix from $1,950 2023-11-22
Giflib HIGH 7.1
CVE-2023-48161

Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB functio…

No fix yet
Fix from $1,950 2023-11-22
Tellus Lite V Simulator HIGH 7.8
CVE-2023-40152

When Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file an out of bounds write may occur.

Fix: 4.0.19.0+
Fix from $1,950 2023-11-22
Tellus Lite V Simulator HIGH 7.8
CVE-2023-35127

Stack-based buffer overflow may occur when Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file.

Fix: 4.0.19.0+
Fix from $1,950 2023-11-22
Capnproto CRITICAL 9.8
CVE-2023-48230

Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ HTTP library with WebSocket co…

Patch available
Fix from $2,300 2023-11-21
Jt2go HIGH 7.8
CVE-2021-38405

The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition while parsing specially crafted PDF files. An att…

Fix: 13.1.0.8 / 13.2.0.7+
Fix from $1,950 2023-11-21
Zephyr CRITICAL 9.8
CVE-2023-5055

Possible variant of CVE-2021-3434 in function le_ecred_reconf_req.

Fix: after 3.4.0
Fix from $2,300 2023-11-21
Firefox HIGH 8.8
CVE-2023-6212

Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we p…

Fix: 115.5 / 115.5.0+
Fix from $1,950 2023-11-21
Firefox HIGH 8.8
CVE-2023-6213

Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the…

Fix: 120.0+
Fix from $1,950 2023-11-21
Nessus MEDIUM 6.5
CVE-2023-6062

An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could al…

Fix: 10.5.7 / 10.6.3+
Fix from $1,600 2023-11-20
Nessus MEDIUM 6.5
CVE-2023-6178

An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules var…

Fix: 10.4.4+
Fix from $1,600 2023-11-20
Ax1803 Firmware HIGH 7.5
CVE-2023-48109

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentControlInfo . This vulnerability…

No fix yet
Fix from $1,950 2023-11-20