Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
CRITICAL 9.8 CVE-2023-45482 Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_… Ac10 Firmware No fix yet Fix from $2,3002023-11-29 CRITICAL 9.8 CVE-2023-45483 Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the time parameter in the function compare_parentcont… Ac10 Firmware No fix yet Fix from $2,3002023-11-29 CRITICAL 9.8 CVE-2023-45484 Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWifiG… Ac10 Firmware No fix yet Fix from $2,3002023-11-29 MEDIUM 5.5 CVE-2023-42366 A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. Busybox No fix yet Fix from $1,6002023-11-27 CRITICAL 9.8 CVE-2023-49044 Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the ssid parameter in the function form… Ax1803 Firmware No fix yet Fix from $2,3002023-11-27 CRITICAL 9.8 CVE-2023-49042 Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the sche… Ax1803 Firmware No fix yet Fix from $2,3002023-11-27 HIGH 7.5 CVE-2023-49047 Tenda AX1803 v1.0.0.1 contains a stack overflow via the devName parameter in the function formSetDeviceName. Ax1803 Firmware No fix yet Fix from $1,9502023-11-27 CRITICAL 9.8 CVE-2023-49043EPSS 13% Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the fun… Ax1803 Firmware No fix yet Fix from $2,3002023-11-27 CRITICAL 9.8 CVE-2023-49046 Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function f… Ax1803 Firmware No fix yet Fix from $2,3002023-11-27 HIGH 7.5 CVE-2022-44010 An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on po… Clickhouse 22.3.12.19 / 22.6.6.16+ Fix from $1,9502023-11-23 MEDIUM 6.5 CVE-2022-44011 An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow an… Clickhouse 22.3.12.19 / 22.6.6.16+ Fix from $1,6002023-11-23 CRITICAL 9.8 CVE-2023-29074 A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor … Autocad 2023.1.4 / 2024.1+ Fix from $2,3002023-11-23 CRITICAL 9.8 CVE-2023-29075 A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can … Autocad 2023.1.4 / 2024.1+ Fix from $2,3002023-11-23 HIGH 7.8 CVE-2023-41140 A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious acto… Autocad 2023.1.4 / 2024.1+ Fix from $1,9502023-11-23 CRITICAL 9.8 CVE-2023-29073 A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious ac… Autocad 2023.1.4 / 2024.1+ Fix from $2,3002023-11-23 HIGH 7.5 CVE-2023-48105 An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service v… Webassembly Micro Runtime Patch available Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-48107 Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_has_slash … Minizip Ng Patch available Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-48106 Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_resolve fu… Minizip Ng Patch available Fix from $1,9502023-11-22 HIGH 7.5 CVE-2023-47016 radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h. Radare2 5.9.0+ Fix from $1,9502023-11-22 HIGH 7.1 CVE-2023-48161 Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB functio… Giflib No fix yet Fix from $1,9502023-11-22 HIGH 7.8 CVE-2023-40152 When Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file an out of bounds write may occur. Tellus Lite V Simulator 4.0.19.0+ Fix from $1,9502023-11-22 HIGH 7.8 CVE-2023-35127 Stack-based buffer overflow may occur when Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file. Tellus Lite V Simulator 4.0.19.0+ Fix from $1,9502023-11-22 CRITICAL 9.8 CVE-2023-48230 Cap'n Proto is a data interchange format and capability-based RPC system. In versions 1.0 and 1.0.1, when using the KJ HTTP library with WebSocket co… Capnproto Patch available Fix from $2,3002023-11-21 HIGH 7.8 CVE-2021-38405 The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition while parsing specially crafted PDF files. An att… Jt2go 13.1.0.8 / 13.2.0.7+ Fix from $1,9502023-11-21 CRITICAL 9.8 CVE-2023-5055 Possible variant of CVE-2021-3434 in function le_ecred_reconf_req. Zephyr after 3.4.0 Fix from $2,3002023-11-21 HIGH 8.8 CVE-2023-6212 Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we p… Firefox 115.5 / 115.5.0+ Fix from $1,9502023-11-21 HIGH 8.8 CVE-2023-6213 Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of the… Firefox 120.0+ Fix from $1,9502023-11-21 MEDIUM 6.5 CVE-2023-6062 An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could al… Nessus 10.5.7 / 10.6.3+ Fix from $1,6002023-11-20 MEDIUM 6.5 CVE-2023-6178 An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules var… Nessus 10.4.4+ Fix from $1,6002023-11-20 HIGH 7.5 CVE-2023-48109 Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow via the deviceId parameter in the function saveParentControlInfo . This vulnerability… Ax1803 Firmware No fix yet Fix from $1,9502023-11-20