Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
HIGH 7.8 CVE-2021-40165 A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while pars… Autocad 2019.1.4 / 2020.1.5+ Fix from $1,9502022-10-07 HIGH 7.8 CVE-2022-39852 A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker to perform … Android Mitigation only Fix from $1,9502022-10-07 HIGH 8.8 CVE-2022-41526 TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the ip parameter in the setDiagnosisCfg functio… Nr1800x Firmware No fix yet Fix from $1,9502022-10-06 HIGH 8.8 CVE-2022-41527 TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the pppoeUser parameter in the setOpModeCfg fun… Nr1800x Firmware No fix yet Fix from $1,9502022-10-06 HIGH 8.8 CVE-2022-41528 TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the text parameter in the setSmsCfg function. Nr1800x Firmware No fix yet Fix from $1,9502022-10-06 CRITICAL 9.8 CVE-2022-41522 TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function. Nr1800x Firmware No fix yet Fix from $2,3002022-10-06 HIGH 8.8 CVE-2022-41523 TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the command parameter in the setTracerouteCfg f… Nr1800x Firmware No fix yet Fix from $1,9502022-10-06 HIGH 8.8 CVE-2022-41524 TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the week, sTime, and eTime parameters in the se… Nr1800x Firmware No fix yet Fix from $1,9502022-10-06 HIGH 8.8 CVE-2022-41521 TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the sPort/ePort parameter in the setIpPortFilte… Nr1800x Firmware No fix yet Fix from $1,9502022-10-06 HIGH 8.8 CVE-2022-41520 TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an authenticated stack overflow via the File parameter in the UploadCustomModule fu… Nr1800x Firmware No fix yet Fix from $1,9502022-10-06 HIGH 8.8 CVE-2022-41517 TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow in the lang parameter in the setLanguageCfg function Nr1800x Firmware No fix yet Fix from $1,9502022-10-06 MEDIUM 6.5 CVE-2022-40160 ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to… Commons Jxpath after 1.3 Fix from $1,6002022-10-06 MEDIUM 6.5 CVE-2022-40159 ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to… Commons Jxpath after 1.3 Fix from $1,6002022-10-06 CRITICAL 9.8 CVE-2022-3397 OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. Cx Programmer after 9.78 Fix from $2,3002022-10-06 CRITICAL 9.8 CVE-2022-3398 OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. Cx Programmer after 9.78 Fix from $2,3002022-10-06 CRITICAL 9.8 CVE-2022-3396 OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. Cx Programmer after 9.78 Fix from $2,3002022-10-06 HIGH 8.8 CVE-2021-40556 A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulnerability is caused by the str… Rt Ax56u Firmware No fix yet Fix from $1,9502022-10-06 HIGH 7.8 CVE-2022-41301 A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access… Subassembly Composer 2020.6.3 / 2021.3.2+ Fix from $1,9502022-10-03 HIGH 7.8 CVE-2022-33888 A malicious crafted Dwg2Spd file when processed through Autodesk DWG application could lead to memory corruption vulnerability by write access violat… Autocad 2022.1.3 / 2023.1.1+ Fix from $1,9502022-10-03 HIGH 7.8 CVE-2022-33889 A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the … Autocad 2022.1.3 / 2023.1.1+ Fix from $1,9502022-10-03 HIGH 7.8 CVE-2022-33890 A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access… Autocad 2022.1.3 / 2023.1.1+ Fix from $1,9502022-10-03 HIGH 7.8 CVE-2022-33883 A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications coul… Advanced Material Exchange Mitigation only Fix from $1,9502022-10-03 HIGH 7.8 CVE-2022-33885 A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. T… Autocad 2022.1.3 / 2023.1.1+ Fix from $1,9502022-10-03 HIGH 8.8 CVE-2022-41429 Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag. Bento4 Patch available Fix from $1,9502022-10-03 HIGH 8.8 CVE-2022-41430 Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux. Bento4 Patch available Fix from $1,9502022-10-03 HIGH 8.8 CVE-2022-41428 Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux. Bento4 No fix yet Fix from $1,9502022-10-03 MEDIUM 5.5 CVE-2022-41420 nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component Netwide Assembler No fix yet Fix from $1,6002022-10-03 CRITICAL 9.1 CVE-2022-42002 SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of thes… Sonicjs after 0.6.0 Fix from $2,3002022-10-01 MEDIUM 6.5 CVE-2022-20769 A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent a… Wireless Lan Controller Software 8.10.171.0+ Fix from $1,6002022-09-30 MEDIUM 5.5 CVE-2022-41842 An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc. Xpdf Patch available Fix from $1,6002022-09-30