Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Magic R300 2100m Firmware HIGH 7.2
CVE-2023-33636

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.

Mitigation only
Fix from $1,950 2023-05-31
Magic R300 2100m Firmware HIGH 7.2
CVE-2023-33637

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm.

Mitigation only
Fix from $1,950 2023-05-31
Magic R300 2100m Firmware HIGH 7.2
CVE-2023-33638

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the Edit_BasicSSID_5G interface at /goform/aspForm.

Mitigation only
Fix from $1,950 2023-05-31
Magic R300 2100m Firmware HIGH 7.2
CVE-2023-33639

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the SetMobileAPInfoById interface at /goform/aspForm.

Mitigation only
Fix from $1,950 2023-05-31
X5000r Firmware HIGH 8.8
CVE-2023-33485

TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the add…

No fix yet
Fix from $1,950 2023-05-31
Chrome HIGH 8.8
CVE-2023-2934

Out of bounds memory access in Mojo in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 114.0.5735.90+
Fix from $1,950 2023-05-30
Chrome HIGH 8.8
CVE-2023-2929

Out of bounds write in Swiftshader in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a cra…

Fix: 114.0.5735.90+
Fix from $1,950 2023-05-30
Riot CRITICAL 9.8
CVE-2023-33975

RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In version 20…

Fix: after 2023.01
Fix from $2,300 2023-05-30
Riot HIGH 7.5
CVE-2023-24817

RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to vers…

Fix: 2023.04+
Fix from $1,950 2023-05-30
Ac6 Firmware CRITICAL 9.8
CVE-2023-2923

A vulnerability classified as critical was found in Tenda AC6 US_AC6V1.0BR_V15.03.05.19. Affected by this vulnerability is the function fromDhcpListC…

No fix yet
Fix from $2,300 2023-05-27
Debian Linux HIGH 7.5
CVE-2023-32307

Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.…

Fix: 1.13.15+
Fix from $1,950 2023-05-26
Wireshark MEDIUM 6.5
CVE-2023-2857

BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file

Fix: 3.6.14 / 4.0.6+
Fix from $1,600 2023-05-26
Wireshark MEDIUM 6.5
CVE-2023-2858

NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file

Fix: 3.6.14 / 4.0.6+
Fix from $1,600 2023-05-26
Wireshark MEDIUM 6.5
CVE-2023-2854

BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file

Fix: 3.6.14 / 4.0.6+
Fix from $1,600 2023-05-26
Wireshark MEDIUM 6.5
CVE-2023-2855

Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file

Fix: 3.6.14 / 4.0.6+
Fix from $1,600 2023-05-26
Wireshark MEDIUM 6.5
CVE-2023-2856

VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file

Fix: 3.6.14 / 4.0.6+
Fix from $1,600 2023-05-26
Libjpeg Turbo MEDIUM 6.5
CVE-2023-2804

A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability …

Patch available
Fix from $1,600 2023-05-25
Fedora MEDIUM 6.4
CVE-2023-31130

c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00…

Fix: 1.19.1+
Fix from $1,600 2023-05-25
Htmlunit HIGH 7.5
CVE-2023-2798

Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web p…

Fix: 2.70.0+
Fix from $1,950 2023-05-25
Twister Antivirus HIGH 7.8
CVE-2023-2873

A vulnerability classified as critical was found in Twister Antivirus 8. This vulnerability affects the function 0x804f2143/0x804f217f/0x804f214b/0x8…

Fix: after 8.17
Fix from $1,950 2023-05-24
Half Life HIGH 7.3
CVE-2023-30382

A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privileges by supp…

Mitigation only
Fix from $1,950 2023-05-23
Connect Iq CRITICAL 9.8
CVE-2023-23306

The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in …

Fix: after 4.1.7
Fix from $2,300 2023-05-23
Poweredge R740 Firmware HIGH 7.8
CVE-2023-25537

Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerabilit…

Fix: 2.18.1+
Fix from $1,950 2023-05-22
Libtiff MEDIUM 5.5
CVE-2023-30774

A vulnerability was found in the libtiff library. This flaw causes a heap buffer overflow issue via the TIFFTAG_INKNAMES and TIFFTAG_NUMBEROFINKS val…

Fix: 14.1+
Fix from $1,600 2023-05-19
Libtiff MEDIUM 5.5
CVE-2023-30775

A vulnerability was found in the libtiff library. This security flaw causes a heap buffer overflow in extractContigSamples32bits, tiffcrop.c.

Mitigation only
Fix from $1,600 2023-05-19
Fastgate Vdsl2 Dga4131fwb Firmware HIGH 7.5
CVE-2022-30114

A heap-based buffer overflow in a network service in Fastweb FASTGate MediaAccess FGA2130FWB, firmware version 18.3.n.0482_FW_230_FGA2130, and DGA413…

Fix: 18.3.n.0482_fw_233_fga2130 / 18.3.n.0482_fw_264_dga4131+
Fix from $1,950 2023-05-19
Hermes CRITICAL 9.8
CVE-2023-23556

An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attack…

Fix: 2023-02-02+
Fix from $2,300 2023-05-18
Netconsd CRITICAL 9.8
CVE-2023-28753

netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to cre…

Patch available
Fix from $2,300 2023-05-18
F7c063 Firmware CRITICAL 9.8
CVE-2023-27217

A stack-based buffer overflow in the ChangeFriendlyName() function of Belkin Smart Outlet V2 F7c063 firmware_2.00.11420.OWRT.PVT_SNSV2 allows attacke…

No fix yet
Fix from $2,300 2023-05-18
Binutils MEDIUM 6.5
CVE-2023-1972

A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.

Fix: after 2.40
Fix from $1,600 2023-05-17