Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Mjson HIGH 7.5
CVE-2023-34611

An issue was discovered mjson thru 1.4.1 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cycl…

Fix: after 1.4.1
Fix from $1,950 2023-06-14
Ecostruxure Foxboro Dcs Control Core Services HIGH 7.8
CVE-2023-2569

A CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, elevation of privilege, and potentially kernel executio…

Mitigation only
Fix from $1,950 2023-06-14
Tl Wpa7510 Firmware CRITICAL 9.8
CVE-2023-29562

TP-Link TL-WPA7510 (EU)_V2_190125 was discovered to contain a stack overflow via the operation parameter at /admin/locale.

No fix yet
Fix from $2,300 2023-06-13
Jhead CRITICAL 9.8
CVE-2022-28550

Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it d…

Patch available
Fix from $2,300 2023-06-13
Frenic Rhc Loader HIGH 7.8
CVE-2023-29160

Stack-based buffer overflow vulnerability exists in FRENIC RHC Loader v1.1.0.3. If a user opens a specially crafted FNE file, sensitive information o…

Fix: after 1.1.0.3
Fix from $1,950 2023-06-13
Jt2go HIGH 7.8
CVE-2023-33124

A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visua…

Fix: 13.2.0.13 / 13.3.0.10+
Fix from $1,950 2023-06-13
Fortiproxy HIGH 7.8
CVE-2023-22639

A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, Fo…

Fix: after 7.2.3
Fix from $1,950 2023-06-13
Fortiproxy CRITICAL 9.8
CVE-2023-27997 KEVEPSS 86%

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version …

Fix: after 7.2.4
Fix from $2,300 2023-06-13
Dir 600 Firmware CRITICAL 9.8
CVE-2023-33626

D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary.

No fix yet
Fix from $2,300 2023-06-12
Rt N10lx Firmware HIGH 7.5
CVE-2023-34940

Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html. NOTE: This vulnerability only a…

No fix yet
Fix from $1,950 2023-06-12
Rt N10lx Firmware HIGH 7.5
CVE-2023-34942

Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the mac parameter at /start-apply.html. NOTE: This vulnerability only a…

No fix yet
Fix from $1,950 2023-06-12
Ec70 Firmware HIGH 8.8
CVE-2023-28478

TP-Link EC-70 devices through 2.3.4 Build 20220902 rel.69498 have a Buffer Overflow.

Fix: after 2.3.4_build_20220902_rel.69498
Fix from $1,950 2023-06-12
Nanomq HIGH 7.8
CVE-2023-34488

NanoMQ 0.17.5 has a one-byte heap-based buffer over-read in the conn_handler function of mqtt_parser.c when it processes malformed messages.

Patch available
Fix from $1,950 2023-06-12
Datadirect Odbc Oracle Wire Protocol Driver CRITICAL 9.8
CVE-2023-34364

A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large value for certain options of a…

Fix: 08.02.2770+
Fix from $2,300 2023-06-09
Ac10 Firmware CRITICAL 9.8
CVE-2023-34566

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.

Mitigation only
Fix from $2,300 2023-06-08
Ac10 Firmware MEDIUM 6.7
CVE-2023-34567

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.

Mitigation only
Fix from $1,600 2023-06-08
Ac10 Firmware MEDIUM 6.7
CVE-2023-34568

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.

Mitigation only
Fix from $1,600 2023-06-08
Ac10 Firmware MEDIUM 6.7
CVE-2023-34569

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.

Mitigation only
Fix from $1,600 2023-06-08
Ac10 Firmware MEDIUM 6.7
CVE-2023-34570

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName.

Mitigation only
Fix from $1,600 2023-06-08
Ac10 Firmware MEDIUM 6.7
CVE-2023-34571

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /goform/WifiGuestSet.

Mitigation only
Fix from $1,600 2023-06-08
Nanomq HIGH 7.5
CVE-2023-33658

A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_msg_get_pub_pid() in the…

Patch available
Fix from $1,950 2023-06-08
Nanomq HIGH 7.5
CVE-2023-33660

A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function copyn_str() in the file mqtt…

Patch available
Fix from $1,950 2023-06-08
Cncsoft B HIGH 7.8
CVE-2023-24014

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to heap-based buffer overflow, which could allow an attacker to exec…

Fix: after 1.0.0.4
Fix from $1,950 2023-06-07
Jt2go HIGH 7.8
CVE-2023-1709

Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could …

Fix: 13.2.0.13 / 13.3.0.9+
Fix from $1,950 2023-06-07
Agent HIGH 8.1
CVE-2023-1388

A heap-based overflow vulnerability in TA prior to version 5.7.9 allows a remote user to alter the page heap in the macmnsvc process memory block, re…

Fix: 5.7.9+
Fix from $1,950 2023-06-07
Wireshark MEDIUM 6.5
CVE-2023-0666

Due to failure in validating the length provided by an attacker-crafted RTPS packet, Wireshark version 4.0.5 and prior, by default, is susceptible to…

Fix: 4.0.6+
Fix from $1,600 2023-06-07
Wireshark MEDIUM 6.5
CVE-2023-0667

Due to failure in validating the length provided by an attacker-crafted MSMMS packet, Wireshark version 4.0.5 and prior, in an unusual configuration,…

Fix: 4.0.6+
Fix from $1,600 2023-06-07
Wireshark MEDIUM 6.5
CVE-2023-0668

Due to failure in validating the length provided by an attacker-crafted IEEE-C37.118 packet, Wireshark version 4.0.5 and prior, by default, is suscep…

Fix: 3.6.14 / 4.0.6+
Fix from $1,600 2023-06-07
Imagemagick MEDIUM 5.5
CVE-2023-2157

A heap-based buffer overflow vulnerability was found in the ImageMagick package that can lead to the application crashing.

Fix: 7.1.1-9+
Fix from $1,600 2023-06-06
Axtls MEDIUM 5.5
CVE-2023-33613

axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c. This vulnerability allows atta…

No fix yet
Fix from $1,600 2023-06-06