Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Magic B1st Firmware HIGH 7.5
CVE-2023-34928

A stack overflow in the Edit_BasicSSID function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST requ…

No fix yet
Fix from $1,950 2023-06-28
Magic B1st Firmware HIGH 7.5
CVE-2023-34929

A stack overflow in the AddMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

No fix yet
Fix from $1,950 2023-06-28
Magic B1st Firmware HIGH 7.5
CVE-2023-34930

A stack overflow in the EditMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

No fix yet
Fix from $1,950 2023-06-28
Magic B1st Firmware HIGH 7.5
CVE-2023-34931

A stack overflow in the EditWlanMacList function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST req…

No fix yet
Fix from $1,950 2023-06-28
Magic B1st Firmware HIGH 7.5
CVE-2023-34932

A stack overflow in the UpdateWanMode function of H3C Magic B1STV100R012 allows attackers to cause a Denial of Service (DoS) via a crafted POST reque…

No fix yet
Fix from $1,950 2023-06-28
Alias HIGH 7.8
CVE-2023-29068

A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction w…

Fix: 2020.1.6 / 2021.1.3+
Fix from $1,950 2023-06-27
Magic B1stw Firmware HIGH 7.5
CVE-2023-34924

H3C Magic B1STW B1STV100R012 was discovered to contain a stack overflow via the function SetAPInfoById. This vulnerability allows attackers to cause …

Mitigation only
Fix from $1,950 2023-06-26
Thinkpad E14 Firmware MEDIUM 6.7
CVE-2023-2290

A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute ar…

Mitigation only
Fix from $1,600 2023-06-26
Nettle CRITICAL 9.8
CVE-2023-36660

The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.

Patch available
Fix from $2,300 2023-06-25
Alias HIGH 7.8
CVE-2023-25003

A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities.…

Fix: 2020.1.6 / 2021.1.3+
Fix from $1,950 2023-06-23
Safari HIGH 8.8
CVE-2023-32435 KEVEPSS 23%

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 1…

Fix: 13.3 / 15.7.7+
Fix from $1,950 2023-06-23
macOS HIGH 7.8
CVE-2023-32380

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS V…

Fix: 11.7.7 / 12.6.6+
Fix from $1,950 2023-06-23
macOS MEDIUM 5.5
CVE-2023-32395

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. A…

Fix: 11.7.7 / 12.6.6+
Fix from $1,600 2023-06-23
Ipados HIGH 7.5
CVE-2023-32397

A logic issue was addressed with improved state management. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey…

Fix: 11.7.7 / 12.6.6+
Fix from $1,950 2023-06-23
macOS HIGH 7.8
CVE-2023-23516

The issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. An app…

Fix: 11.7.3 / 12.6.3+
Fix from $1,950 2023-06-23
Libredwg HIGH 8.8
CVE-2023-36271

LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.

Fix: after 0.12.5
Fix from $1,950 2023-06-23
Libredwg HIGH 8.8
CVE-2023-36272

LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.

Fix: after 0.12.5
Fix from $1,950 2023-06-23
Libredwg HIGH 8.8
CVE-2023-36273

LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.

No fix yet
Fix from $1,950 2023-06-23
Libredwg HIGH 8.8
CVE-2023-36274

LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.

Fix: after 0.12.5
Fix from $1,950 2023-06-23
Sngrep HIGH 7.8
CVE-2023-36192

Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_ws_check_packet at /src/capture.c.

No fix yet
Fix from $1,950 2023-06-23
Gifsicle HIGH 7.8
CVE-2023-36193

Gifsicle v1.9.3 was discovered to contain a heap buffer overflow via the ambiguity_error component at /src/clp.c.

Patch available
Fix from $1,950 2023-06-23
Vcenter Server CRITICAL 9.8
CVE-2023-20894EPSS 34%

The VMware vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network …

Fix: 7.0+
Fix from $2,300 2023-06-22
Vcenter Server CRITICAL 9.8
CVE-2023-20895

The VMware vCenter Server contains a memory corruption vulnerability in the implementation of the DCERPC protocol. A malicious actor with network acc…

Fix: 7.0+
Fix from $2,300 2023-06-22
Vcenter Server CRITICAL 9.8
CVE-2023-20892

The vCenter Server contains a heap overflow vulnerability due to the usage of uninitialized memory in the implementation of the DCERPC protocol. A ma…

Fix: 7.0+
Fix from $2,300 2023-06-22
Z\/ip Gateway Sdk HIGH 8.8
CVE-2023-0972

Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack bu…

Fix: after 7.18.01
Fix from $1,950 2023-06-21
Unify Software Development Kit HIGH 8.8
CVE-2023-3110

Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buf…

Fix: after 1.3.1
Fix from $1,950 2023-06-21
Z\/ip Gateway Sdk MEDIUM 6.8
CVE-2023-0970

Multiple buffer overflow vulnerabilities in SiLabs Z/IP Gateway SDK version 7.18.01 and earlier allow an attacker with invasive physical access to a …

Fix: after 7.18.01
Fix from $1,600 2023-06-21
Debian Linux HIGH 7.5
CVE-2023-2911

If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`…

Fix: after 9.18.15
Fix from $1,950 2023-06-21
Emui HIGH 7.5
CVE-2022-48486

Configuration defects in the secure OS module.Successful exploitation of this vulnerability will affect availability.

No fix yet
Fix from $1,950 2023-06-19
Firefox CRITICAL 9.8
CVE-2023-34416

Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we…

Fix: 102.12 / 114.0+
Fix from $2,300 2023-06-19