Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Autocad HIGH 7.8
CVE-2023-27914

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 can be used to write beyond the allocated buffer causing a Stack Buffer Ov…

Fix: 2023.1.3+
Fix from $1,950 2023-04-14
Autocad HIGH 7.8
CVE-2023-27915

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by read access violation. Th…

Fix: 2023.1.3+
Fix from $1,950 2023-04-14
Autocad HIGH 7.8
CVE-2023-29067

A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. T…

Fix: 2023.1.3+
Fix from $1,950 2023-04-14
Mp4v2 HIGH 8.8
CVE-2023-29584

mp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the MP4GetVideoProfileLevel function at /src/mp4.cpp.

No fix yet
Fix from $1,950 2023-04-14
Ncurses HIGH 7.8
CVE-2023-29491

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data …

Fix: 6.4+
Fix from $1,950 2023-04-14
Substance 3d Designer HIGH 7.8
CVE-2023-26416

Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary cod…

Fix: after 12.4.0
Fix from $1,950 2023-04-13
Substance 3d Designer HIGH 7.8
CVE-2023-26415

Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code exec…

Fix: after 12.4.0
Fix from $1,950 2023-04-13
Substance 3d Designer HIGH 7.8
CVE-2023-26412

Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary co…

Fix: after 12.4.0
Fix from $1,950 2023-04-13
Substance 3d Designer HIGH 7.8
CVE-2023-26413

Adobe Substance 3D Designer version 12.4.0 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary cod…

Fix: after 12.4.0
Fix from $1,950 2023-04-13
Mdm8207 Firmware CRITICAL 9.8
CVE-2022-25740

Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of the iface

Mitigation only
Fix from $2,300 2023-04-13
Mdm8207 Firmware CRITICAL 9.8
CVE-2022-25678

Memory correction in modem due to buffer overwrite during coap connection

Mitigation only
Fix from $2,300 2023-04-13
Substance 3d Stager HIGH 7.8
CVE-2023-26394

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code e…

Fix: after 2.0.1
Fix from $1,950 2023-04-12
Substance 3d Stager HIGH 7.8
CVE-2023-26390

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code …

Fix: after 2.0.1
Fix from $1,950 2023-04-12
Substance 3d Stager HIGH 7.8
CVE-2023-26383

Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code …

Fix: after 2.0.1
Fix from $1,950 2023-04-12
Digital Editions HIGH 7.8
CVE-2023-21582

Adobe Digital Editions version 4.5.11.187303 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code ex…

Fix: 4.5.11.187658+
Fix from $1,950 2023-04-12
Fedora MEDIUM 5.5
CVE-2023-1906

A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker …

Fix: 6.9.12-84+
Fix from $1,600 2023-04-12
Acrobat HIGH 7.8
CVE-2023-26395

Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an out-of-bounds write vulnerability that cou…

Fix: after 23.001.20093
Fix from $1,950 2023-04-12
Dimension HIGH 7.8
CVE-2023-26372

Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the …

Fix: after 3.4.8
Fix from $1,950 2023-04-12
Dimension HIGH 7.8
CVE-2023-26373

Adobe Dimension version 3.4.8 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the …

Fix: after 3.4.8
Fix from $1,950 2023-04-12
Connman MEDIUM 6.5
CVE-2023-28488

client.c in gdhcp in ConnMan through 1.41 could be used by network-adjacent attackers (operating a crafted DHCP server) to cause a stack-based buffer…

Fix: after 1.41
Fix from $1,600 2023-04-12
Insydeh2o HIGH 8.8
CVE-2023-22613

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An at…

Mitigation only
Fix from $1,950 2023-04-11
Windows 10 1507 HIGH 7.8
CVE-2023-28252 KEVEPSS 49%

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Fix: 10.0.10240.19869 / 10.0.14393.5850+
Fix from $1,950 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26551

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write in the cp<cpdec while loop. An adversary may be able to attack a client ntpq p…

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26552

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a decimal point. An adversary may be able to attack a client ntpq …

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26553

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when copying the trailing number. An adversary may be able to attack a client …

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 5.6
CVE-2023-26554

mstolfp in libntp/mstolfp.c in NTP 4.2.8p15 has an out-of-bounds write when adding a '\0' character. An adversary may be able to attack a client ntpq…

Mitigation only
Fix from $1,600 2023-04-11
Ntp MEDIUM 6.4
CVE-2023-26555

praecis_parse in ntpd/refclock_palisade.c in NTP 4.2.8p15 has an out-of-bounds write. Any attack method would be complex, e.g., with a manipulated GP…

Mitigation only
Fix from $1,600 2023-04-11
Insydeh2o HIGH 8.8
CVE-2023-22612

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malfor…

Mitigation only
Fix from $1,950 2023-04-11
Insydeh2o HIGH 8.8
CVE-2023-22614

An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard update…

No fix yet
Fix from $1,950 2023-04-11
Insydeh2o HIGH 8.4
CVE-2023-22615

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI subfunction execution may corrupt SMRAM. An attacker can p…

Mitigation only
Fix from $1,950 2023-04-11