Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
HIGH 7.8 CVE-2023-42902 Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously c… macOS 14.2+ Fix from $1,9502023-12-12 HIGH 7.8 CVE-2023-42903 Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in macOS Sonoma 14.2. Processing a maliciously c… macOS 14.2+ Fix from $1,9502023-12-12 CRITICAL 9.8 CVE-2023-49417 TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg. A7000r Firmware No fix yet Fix from $2,3002023-12-11 CRITICAL 9.8 CVE-2023-49418 TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules. A7000r Firmware No fix yet Fix from $2,3002023-12-11 HIGH 7.5 CVE-2023-49355 decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same… Jq Patch available Fix from $1,9502023-12-11 CRITICAL 9.8 CVE-2023-46932 Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitrary code and cause a denial of… Gpac No fix yet Fix from $2,3002023-12-09 MEDIUM 5.5 CVE-2023-28526 IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a… Informix Dynamic Server Mitigation only Fix from $1,6002023-12-09 MEDIUM 5.5 CVE-2023-28527 IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local… Informix Dynamic Server Mitigation only Fix from $1,6002023-12-09 HIGH 7.8 CVE-2023-28523 IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an… Informix Dynamic Server Mitigation only Fix from $1,9502023-12-09 HIGH 7.5 CVE-2023-49800 `nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no f… Nuxt Api Party after 0.21.3 Fix from $1,9502023-12-09 HIGH 7.8 CVE-2023-48421 In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/platform/pixel/pixel_gpu_slc.c, there is a possible out of … Android Mitigation only Fix from $1,9502023-12-08 CRITICAL 9.8 CVE-2023-48423 In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executi… Android Mitigation only Fix from $2,3002023-12-08 HIGH 7.5 CVE-2023-48403 In sms_DecodeCodedTpMsg of sms_PduCodec.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote informatio… Android Mitigation only Fix from $1,9502023-12-08 CRITICAL 9.8 CVE-2023-49007EPSS 9% In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd. Rbr750 Firmware 7.2.6.21+ Fix from $2,3002023-12-08 HIGH 8.8 CVE-2023-49465 Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc. Libde265 Patch available Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-49467 Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at mo… Libde265 Patch available Fix from $1,9502023-12-07 HIGH 8.8 CVE-2023-49468 Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc. Libde265 Patch available Fix from $1,9502023-12-07 CRITICAL 9.8 CVE-2023-49404 Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet. W30e Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49405 Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg. W30e Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49408 Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name. Ax3 Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49411 Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode. W30e Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49402 Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg. W30e Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49403 Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools. W30e Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49410 Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status. W30e Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49999 Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition. W30e Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-50000 Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode. W30e Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-50001 Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline. W30e Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-50002 Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode. W30e Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49430 Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg. Ax9 Firmware No fix yet Fix from $2,3002023-12-07 CRITICAL 9.8 CVE-2023-49432 Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg. Ax9 Firmware No fix yet Fix from $2,3002023-12-07