VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2023-52494High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Add alignment check for event ring read pointer Though we do check the event ring read pointer by "is_valid_ring_ptr" to make sure it is in the buffer …

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Add alignment check for event ring read pointer Though we do check the event ring read pointer by "is_valid_ring_ptr" to make sure it is in the buffer …

▾ Twilightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2023-52497High· 7.1
2y ago

In the Linux kernel, the following vulnerability has been resolved: erofs: fix lz4 inplace decompression Currently EROFS can map another compressed buffer for inplace decompression, that was used to handle the cases that some pages of …

In the Linux kernel, the following vulnerability has been resolved: erofs: fix lz4 inplace decompression Currently EROFS can map another compressed buffer for inplace decompression, that was used to handle the cases that some pages of …

▾ Twilightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2024-26586High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption When tc filters are first added to a net device, the corresponding local port gets bound to an ACL group in the device

In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption When tc filters are first added to a net device, the corresponding local port gets bound to an ACL group in the device. …

▾ Twilightlinux · linux_kernelEPSS 0.25%via NVD
CVE-2024-21762Critical· 9.8CISA KEV0dayPoC
2y ago

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7…

▾ Hadalfortinet · fortiproxyEPSS 83%via NVD
CVE-2023-40548High· 7.4
2y ago

A buffer overflow was found in Shim in the 32-bit system

A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation …

▾ Twilightredhat · shimEPSS 0.44%via NVD
CVE-2023-52355High· 7.5
2y ago

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smal…

▾ Twilightlibtiff · libtiffEPSS 1.8%via NVD
CVE-2023-40547High· 8.3
2y ago

A remote code execution vulnerability was found in Shim

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a complet…

▾ Twilightredhat · shimEPSS 5.4%via NVD
CVE-2024-0646High· 7.0
2y ago

An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination

An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially …

▾ Twilightlinux · linux_kernelEPSS 0.31%via NVD
CVE-2023-6879Critical· 9.0
2y ago

Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().

Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().

▾ Midnightaomedia · aomediaEPSS 1.2%via NVD
CVE-2023-6931High· 7.8PoC
2y ago

A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increme…

A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increme…

▾ Midnightlinux · linux_kernelEPSS 0.71%via NVD
CVE-2023-4692High· 7.5
2y ago

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack…

▾ Twilightgnu · grub2EPSS 0.54%via NVD
CVE-2023-5367High· 7.8
2y ago

A out-of-bounds write flaw was found in the xorg-x11-server

A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRCha…

▾ Twilightx.org · x_serverEPSS 0.62%via NVD
CVE-2023-42753High· 7.0
3y ago

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel

An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decre…

▾ Twilightlinux · linux_kernelEPSS 0.51%via NVD
CVE-2023-4751High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

▾ Twilightneovim · neovimEPSS 0.56%via NVD
CVE-2023-4738High· 7.8
3y ago

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

▾ Twilightneovim · neovimEPSS 0.60%via NVD
CVE-2023-4735High· 7.8
3y ago

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

▾ Twilightvim · vimEPSS 0.60%via NVD
CVE-2020-19190Medium· 6.5
3y ago

Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

▾ Sunlitinvisible-island · ncursesEPSS 1.8%via NVD
CVE-2020-19189Medium· 6.5
3y ago

Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

▾ Sunlitinvisible-island · ncursesEPSS 2.2%via NVD
CVE-2020-19188Medium· 6.5
3y ago

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

▾ Sunlitinvisible-island · ncursesEPSS 1.8%via NVD
CVE-2020-19187Medium· 6.5
3y ago

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

▾ Sunlitinvisible-island · ncursesEPSS 1.8%via NVD
CVE-2020-19186Medium· 6.5
3y ago

Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

▾ Sunlitinvisible-island · ncursesEPSS 1.8%via NVD
CVE-2020-19185Medium· 6.5
3y ago

Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.

▾ Sunlitinvisible-island · ncursesEPSS 1.8%via NVD
CVE-2022-48174Critical· 9.8
3y ago

There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35

There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.

▾ Midnightbusybox · busyboxEPSS 3.2%via NVD
CVE-2023-35177High· 8.8
3y ago

Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compact font format parser.

Certain HP LaserJet Pro print products are potentially vulnerable to a stack-based buffer overflow related to the compact font format parser.

▾ Twilighthp · w1a75a_firmwareEPSS 0.37%via NVD
CVE-2023-27997Critical· 9.8CISA KEV0dayPoC
3y ago

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, versio…

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, versio…

▾ Hadalfortinet · fortiproxyEPSS 86%via NVD
CVE-2023-29551High· 8.8
3y ago

Memory safety bugs present in Firefox 111

Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox f…

▾ Twilightmozilla · firefoxEPSS 0.52%via NVD
CVE-2023-27973Critical· 9.8
3y ago

Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.

Certain HP LaserJet Pro print products are potentially vulnerable to Heap Overflow and/or Remote Code Execution.

▾ Midnighthp · laserjet_pro_m304-m305_w1a46a_firmwareEPSS 1.5%via NVD
CVE-2023-29491High· 7.8
3y ago

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO…

ncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via malformed data in a terminfo database file that is found in $HOME/.terminfo or reached via the TERMINFO…

▾ Twilightinvisible-island · ncursesEPSS 0.93%via NVD
CVE-2023-23376High· 7.8CISA KEV0day
3y ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 11%via NVD
CVE-2022-37325High· 7.5
3y ago

In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.

In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.

▾ Twilightsangoma · asteriskEPSS 1.2%via NVD
CWE-787 vulnerabilities (CVEs) — page 24 · VulnSea