Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Ax3 Firmware HIGH 7.5
CVE-2022-24145

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formWifiBasicSet. This vulnerability allows attackers to cause a…

No fix yet
Fix from $1,950 2022-02-04
Ax3 Firmware HIGH 7.5
CVE-2022-24146

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetQosBand. This vulnerability allows attackers to cause a D…

No fix yet
Fix from $1,950 2022-02-04
G1 Firmware HIGH 7.5
CVE-2021-45988

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDnsForward. This vulnerability allows…

Mitigation only
Fix from $1,950 2022-02-04
G1 Firmware HIGH 7.5
CVE-2021-45989

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function guestWifiRuleRefresh. This vulnerability all…

Mitigation only
Fix from $1,950 2022-02-04
G1 Firmware HIGH 7.5
CVE-2021-45991

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddVpnUsers. This vulnerability allows a…

Mitigation only
Fix from $1,950 2022-02-04
G1 Firmware HIGH 7.5
CVE-2021-45992

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetQvlanList. This vulnerability allows …

Mitigation only
Fix from $1,950 2022-02-04
G1 Firmware HIGH 7.5
CVE-2021-45993

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formIPMacBindModify. This vulnerability allo…

Mitigation only
Fix from $1,950 2022-02-04
G1 Firmware HIGH 7.5
CVE-2021-45994

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formDelDhcpRule. This vulnerability allows a…

Mitigation only
Fix from $1,950 2022-02-04
G1 Firmware HIGH 7.5
CVE-2021-45995

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetStaticRoute. This vulnerability allow…

Mitigation only
Fix from $1,950 2022-02-04
G1 Firmware HIGH 7.5
CVE-2021-45996

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetPortMapping. This vulnerability allow…

No fix yet
Fix from $1,950 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-21740

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` is vulnerable to a heap overflow. The fix wi…

Fix: after 2.6.2
Fix from $1,950 2022-02-03
Insydeh2o MEDIUM 6.7
CVE-2021-42059

An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05.26.41, Kernel 5.3 before 05.…

Fix: 5.08.41 / 5.16.41+
Fix from $1,600 2022-02-03
Insydeh2o HIGH 8.2
CVE-2021-42554

An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 befor…

Fix: 5.08.42 / 5.16.42+
Fix from $1,950 2022-02-03
Insydeh2o HIGH 8.2
CVE-2021-43615

An issue was discovered in HddPassword in Insyde InsydeH2O with kernel 5.1 before 05.16.23, 5.2 before 05.26.23, 5.3 before 05.35.23, 5.4 before 05.4…

Fix: 5.16.23 / 5.23.22+
Fix from $1,950 2022-02-03
Insydeh2o HIGH 7.5
CVE-2022-24030

An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulnerability allows an attacker to w…

Fix: 5.08.41 / 5.16.41+
Fix from $1,950 2022-02-03
Insydeh2o HIGH 8.2
CVE-2022-24031

An issue was discovered in NvmExpressDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulnerability allows an attacker t…

Fix: 5.16.42 / 5.26.42+
Fix from $1,950 2022-02-03
Insydeh2o HIGH 7.5
CVE-2021-43522

An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 2021-11-08, 5.2 through 2021-11-08, and 5.3 through 2021-11-08. A StorageSecurity…

Fix: 5.14.34 / 5.24.34+
Fix from $1,950 2022-02-03
Jhead MEDIUM 6.1
CVE-2020-26208

JHEAD is a simple command line tool for displaying and some manipulation of EXIF header data embedded in Jpeg images from digital cameras. In affecte…

Fix: 3.04+
Fix from $1,600 2022-02-02
Fortiweb HIGH 7.2
CVE-2021-36193

Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitra…

Fix: 6.2.6 / 6.3.16+
Fix from $1,950 2022-02-02
Itext MEDIUM 6.5
CVE-2022-24197

iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial o…

Fix: 7.2.2+
Fix from $1,600 2022-02-01
Fedora HIGH 7.8
CVE-2022-0417

Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4245+
Fix from $1,950 2022-02-01
Fedora HIGH 7.8
CVE-2022-0408

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4247+
Fix from $1,950 2022-01-30
Vim HIGH 7.8
CVE-2022-0407

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4219+
Fix from $1,950 2022-01-30
Debian Linux HIGH 7.8
CVE-2022-0392

Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.

Fix: 8.2.4218 / 12.6+
Fix from $1,950 2022-01-28
Enterprise Linux Server Update Services For Sap Solutions HIGH 7.8
CVE-2021-4034 KEVEPSS 95%

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg…

Patch available
Fix from $1,950 2022-01-28
Rlc 410w Firmware CRITICAL 9.8
CVE-2022-21217

An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted networ…

Mitigation only
Fix from $2,300 2022-01-28
Rlc 410w Firmware HIGH 8.2
CVE-2022-21796

A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-craft…

Mitigation only
Fix from $1,950 2022-01-28
Guicon HIGH 7.8
CVE-2021-22807

A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded int…

Fix: after 2.0
Fix from $1,950 2022-01-28
Mjs HIGH 7.8
CVE-2021-46522

Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via /usr/lib/x86_64-linux-gnu/libasan.so.4+0xaff53.

No fix yet
Fix from $1,950 2022-01-27
Mjs HIGH 7.8
CVE-2021-46523

Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via to_json_or_debug at mjs/src/mjs_json.c.

No fix yet
Fix from $1,950 2022-01-27