VulnSea

CWE-119

CVEs classified under CWE-119, newest first.

290 CVEsRSS

CVE-2025-10225High· 7.5
1y ago

Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cau…

Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) in the OpenSSL-based session module in AxxonSoft Axxon One (C-Werk) 2.0.6 and earlier on Windows allows a remote attacker under high load conditions to cau…

▾ Twilightaxxonsoft · axxon_oneEPSS 0.40%via NVD
CVE-2025-9813High· 8.8
1y ago

A vulnerability was identified in Tenda CH22 1.0.0.1

A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /goform/SetSambaConf. The manipulation of the argument samba_userNameSda leads to buffer overflow. It is possible to initi…

▾ Twilighttenda · ch22_firmwareEPSS 0.87%via NVD
CVE-2025-9812High· 8.8
1y ago

A vulnerability was determined in Tenda CH22 1.0.0.1

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file /goform/exeCommand. Executing manipulation of the argument cmdinput can lead to buffer overflow. The attack may be p…

▾ Twilighttenda · ch22_firmwareEPSS 0.66%via NVD
CVE-2025-9791High· 8.8
1y ago

A weakness has been identified in Tenda AC20 16.03.08.05

A weakness has been identified in Tenda AC20 16.03.08.05. This vulnerability affects unknown code of the file /goform/fromAdvSetMacMtuWan. This manipulation of the argument wanMTU causes stack-based buffer overflow. Remote exploitation o…

▾ Twilighttenda · ac20_firmwareEPSS 0.85%via NVD
CVE-2025-9783High· 8.8
1y ago

A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423

A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423. This issue affects the function sub_418030 of the file /boafrm/formParentControl. Executing manipulation of the argument submit-url can lead to buffer overflow. The a…

▾ Twilighttotolink · a702r_firmwareEPSS 0.66%via NVD
CVE-2025-9782High· 8.8
1y ago

A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423

A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423. This vulnerability affects the function sub_4466F8 of the file /boafrm/formOneKeyAccessButton. Performing manipulation of the argument submit-url results in buffer overflo…

▾ Twilighttotolink · a702r_firmwareEPSS 0.66%via NVD
CVE-2025-9781High· 8.8
1y ago

A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423

A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423. This affects the function sub_4162DC of the file /boafrm/formFilter. Such manipulation of the argument ip6addr leads to buffer overflow. The attack can be launched re…

▾ Twilighttotolink · a702r_firmwareEPSS 0.66%via NVD
CVE-2025-9780High· 8.8
1y ago

A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423

A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this issue is the function sub_419BE0 of the file /boafrm/formIpQoS. This manipulation of the argument mac causes buffer overflow. The attack can be initiated remo…

▾ Twilighttotolink · a702r_firmwareEPSS 0.66%via NVD
CVE-2025-9779High· 8.8
1y ago

A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423

A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this vulnerability is the function sub_4162DC of the file /boafrm/formFilter. The manipulation of the argument ip6addr results in buffer overflow. It is pos…

▾ Twilighttotolink · a702r_firmwareEPSS 0.66%via NVD
CVE-2025-43214Medium· 6.5
1y ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an une…

▾ Sunlitapple · safariEPSS 1.00%via NVD
CVE-2025-43213Medium· 6.5
1y ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to an une…

▾ Sunlitapple · safariEPSS 0.76%via NVD
CVE-2025-31277High· 8.8CISA KEVPoC
1y ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory…

▾ Abyssalapple · safariEPSS 1.6%via NVD
CVE-2025-31223High· 8.0
1y ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.

▾ Twilightapple · safariEPSS 0.57%via NVD
CVE-2025-26597High· 7.8
1y ago

A buffer overflow flaw was found in X.Org and Xwayland

A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 but leave the key actions unchanged. If the same function is later called with a non-zer…

▾ Twilighttigervnc · tigervncEPSS 0.44%via NVD
CVE-2024-30090High· 7.0PoC
2y ago

Microsoft Streaming Service Elevation of Privilege Vulnerability

Microsoft Streaming Service Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · windows_10_1507EPSS 2.0%via NVD
CVE-2024-22373High· 8.1
2y ago

An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23

An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide…

▾ Twilightmalaterre · grassroots_dicomEPSS 1.7%via NVD
CVE-2021-47014High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix wild memory access when clearing fragments while testing re-assembly/re-fragmentation using act_ct, it's possible to observe a crash like the fo…

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix wild memory access when clearing fragments while testing re-assembly/re-fragmentation using act_ct, it's possible to observe a crash like the fo…

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVE-2024-26589High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject variable offset alu on PTR_TO_FLOW_KEYS For PTR_TO_FLOW_KEYS, check_flow_keys_access() only uses fixed off for validation

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject variable offset alu on PTR_TO_FLOW_KEYS For PTR_TO_FLOW_KEYS, check_flow_keys_access() only uses fixed off for validation. However, variable offset ptr alu…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2023-52444High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid dirent corruption As Al reported in link[1]: f2fs_rename() ... if (old_dir != new_dir && !whiteout) f2fs_set_link(old_inode, old_dir_entry, …

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid dirent corruption As Al reported in link[1]: f2fs_rename() ... if (old_dir != new_dir && !whiteout) f2fs_set_link(old_inode, old_dir_entry, …

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2023-52441Critical· 9.1
2y ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negoti…

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negoti…

▾ Midnightlinux · linux_kernelEPSS 0.68%via NVD
CVE-2023-52440Critical· 9.8PoC
2y ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in…

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in…

▾ Abyssallinux · linux_kernelEPSS 22%via NVD
CVE-2023-52434High· 8.1
2y ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts(). This fixes follow…

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts(). This fixes follow…

▾ Twilightlinux · linux_kernelEPSS 1.0%via NVD
CVE-2023-4966Critical· 9.4CISA KEVPoC
2y ago

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

▾ Hadalcitrix · netscaler_application_delivery_controllerEPSS 100%via NVD
CVE-2023-3576Medium· 5.5
2y ago

A memory leak flaw was found in Libtiff's tiffcrop utility

A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, r…

▾ Sunlitlibtiff · libtiffEPSS 0.35%via NVD
CVE-2022-3636Medium· 5.5
3y ago

A vulnerability was identified in Linux Kernel 33fc42de33278b2b3ec6f3390512987bc29a62b7

A vulnerability was identified in Linux Kernel 33fc42de33278b2b3ec6f3390512987bc29a62b7. This affects the function __mtk_ppe_check_skb of the file drivers/net/ethernet/mediatek/mtk_ppe.c of the component Ethernet Handler. Such manipulati…

▾ Sunlitlinux · linux_kernelEPSS 0.35%via NVD
CVE-2022-3534Medium· 5.5
3y ago

A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1

A vulnerability has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. The impacted element is the function btf_dump_name_dups of the file tools/lib/bpf/btf_dump.c of the component libbpf. The manipulation leads to use after…

▾ Sunlitlinux · linux_kernelEPSS 0.91%via NVD
CVE-2022-37434Critical· 9.8PoC⚖ disputed
4y ago

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the af…

▾ Abyssalzlib · zlibEPSS 18%via NVD
CVE-2021-41839High· 8.2
4y ago

An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O

An issue was discovered in NvmExpressDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRA…

▾ Twilightinsyde · insydeh2oEPSS 0.27%via NVD
CVE-2021-41838High· 8.2
4y ago

An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O

An issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of a Numeric …

▾ Twilightinsyde · insydeh2oEPSS 0.30%via NVD
CVE-2021-41837High· 8.2
4y ago

An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O

An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. …

▾ Twilightinsyde · insydeh2oEPSS 0.28%via NVD
CWE-119 vulnerabilities (CVEs) — page 9 · VulnSea