VulnSea

CWE-125

CVEs classified under CWE-125, newest first.

940 CVEsRSS

CVE-2021-4034High· 7.8CISA KEVPoC
4y ago

A local privilege escalation vulnerability was found on polkit's pkexec utility

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current …

▾ Abyssalpolkit_project · polkitEPSS 94%via NVD
CVE-2021-3506High· 7.1
5y ago

An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4

An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to …

▾ Twilightnetapp · cloud_backupEPSS 0.37%via NVD
CVE-2021-27364High· 7.1
5y ago

An issue was discovered in the Linux kernel through 5.11.3

An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.

▾ Twilightnetapp · cloud_backupEPSS 0.97%via NVD
CVE-2020-9666Medium· 5.5
6y ago

Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability

Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

▾ Sunlitadobe · campaignEPSS 2.3%via NVD
CVE-2020-3298High· 7.5
6y ago

A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the relo…

A vulnerability in the Open Shortest Path First (OSPF) implementation of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the relo…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 2.0%via NVD
CVE-2019-11050Medium· 4.8
6y ago

When PHP EXIF extension is parsing EXIF information from an image, e.g

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past…

▾ Sunlitphp · phpEPSS 7.6%via NVD
CVE-2019-11046Low· 3.7
6y ago

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters…

In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string containing characters…

▾ Sunlitphp · phpEPSS 4.1%via NVD
CVE-2019-17595Medium· 5.4
6y ago

There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

▾ Sunlitinvisible-island · ncursesEPSS 2.1%via NVD
CVE-2019-17594Medium· 5.3
6y ago

There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.

▾ Sunlitinvisible-island · ncursesEPSS 0.55%via NVD
CVE-1999-0022High· 7.8
30y ago

Local user gains root privileges via buffer overflow in rdist, via expstr() function.

Local user gains root privileges via buffer overflow in rdist, via expstr() function.

▾ TwilightEPSS 0.49%via NVD
CWE-125 vulnerabilities (CVEs) — page 32 · VulnSea