Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Autocad HIGH 7.8
CVE-2021-40165

A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while pars…

Fix: 2019.1.4 / 2020.1.5+
Fix from $1,950 2022-10-07
Android HIGH 7.8
CVE-2022-39852

A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker to perform …

Mitigation only
Fix from $1,950 2022-10-07
Nr1800x Firmware HIGH 8.8
CVE-2022-41526

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg functio…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41527

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg fun…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41528

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function.

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware CRITICAL 9.8
CVE-2022-41522

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.

No fix yet
Fix from $2,300 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41523

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg f…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41524

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the se…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41521

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilte…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41520

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule fu…

No fix yet
Fix from $1,950 2022-10-06
Nr1800x Firmware HIGH 8.8
CVE-2022-41517

TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function

No fix yet
Fix from $1,950 2022-10-06
Commons Jxpath MEDIUM 6.5
CVE-2022-40160

** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to…

Fix: after 1.3
Fix from $1,600 2022-10-06
Commons Jxpath MEDIUM 6.5
CVE-2022-40159

** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to…

Fix: after 1.3
Fix from $1,600 2022-10-06
Cx Programmer CRITICAL 9.8
CVE-2022-3397

OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.

Fix: after 9.78
Fix from $2,300 2022-10-06
Cx Programmer CRITICAL 9.8
CVE-2022-3398

OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.

Fix: after 9.78
Fix from $2,300 2022-10-06
Cx Programmer CRITICAL 9.8
CVE-2022-3396

OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.

Fix: after 9.78
Fix from $2,300 2022-10-06
Rt Ax56u Firmware HIGH 8.8
CVE-2021-40556

A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the str…

No fix yet
Fix from $1,950 2022-10-06
Subassembly Composer HIGH 7.8
CVE-2022-41301

A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access…

Fix: 2020.6.3 / 2021.3.2+
Fix from $1,950 2022-10-03
Autocad HIGH 7.8
CVE-2022-33888

A malicious crafted Dwg2Spd file when processed through Autodesk DWG application could lead to memory corruption vulnerability by write access violat…

Fix: 2022.1.3 / 2023.1.1+
Fix from $1,950 2022-10-03
Autocad HIGH 7.8
CVE-2022-33889

A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the …

Fix: 2022.1.3 / 2023.1.1+
Fix from $1,950 2022-10-03
Autocad HIGH 7.8
CVE-2022-33890

A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access…

Fix: 2022.1.3 / 2023.1.1+
Fix from $1,950 2022-10-03
Advanced Material Exchange HIGH 7.8
CVE-2022-33883

A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications coul…

Mitigation only
Fix from $1,950 2022-10-03
Autocad HIGH 7.8
CVE-2022-33885

A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. T…

Fix: 2022.1.3 / 2023.1.1+
Fix from $1,950 2022-10-03
Bento4 HIGH 8.8
CVE-2022-41429

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag.

Patch available
Fix from $1,950 2022-10-03
Bento4 HIGH 8.8
CVE-2022-41430

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.

Patch available
Fix from $1,950 2022-10-03
Bento4 HIGH 8.8
CVE-2022-41428

Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.

No fix yet
Fix from $1,950 2022-10-03
Netwide Assembler MEDIUM 5.5
CVE-2022-41420

nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component

No fix yet
Fix from $1,600 2022-10-03
Sonicjs CRITICAL 9.1
CVE-2022-42002

SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of thes…

Fix: after 0.6.0
Fix from $2,300 2022-10-01
Wireless Lan Controller Software MEDIUM 6.5
CVE-2022-20769

A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent a…

Fix: 8.10.171.0+
Fix from $1,600 2022-09-30
Xpdf MEDIUM 5.5
CVE-2022-41842

An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.

Patch available
Fix from $1,600 2022-09-30