VulnSea

CWE-787

CVEs classified under CWE-787, newest first.

807 CVEsRSS

CVE-2022-4141High· 7.8
3y ago

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

▾ Twilightneovim · neovimEPSS 0.45%via NVD
CVE-2022-3324High· 7.8
4y ago

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.

▾ Twilightneovim · neovimEPSS 0.53%via NVD
CVE-2022-3296High· 7.8
4y ago

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

▾ Twilightneovim · neovimEPSS 0.56%via NVD
CVE-2022-37969High· 7.8CISA KEV0dayPoC
4y ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Windows Common Log File System Driver Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 28%via NVD
CVE-2022-38555Critical· 9.8
4y ago

Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.

Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.

▾ Midnightlinksys · e1200_firmwareEPSS 9.8%via NVD
CVE-2022-36233Medium· 5.5
4y ago

Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set

Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd.

▾ Sunlittendacn · ac9_firmwareEPSS 0.25%via NVD
CVE-2022-37434Critical· 9.8PoC⚖ disputed
4y ago

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field

zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the af…

▾ Abyssalzlib · zlibEPSS 18%via NVD
CVE-2022-2294High· 8.8CISA KEV0day
4y ago

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

▾ Abyssalgoogle · chromeEPSS 70%via NVD
CVE-2022-33047Critical· 9.8
4y ago

OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.

OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.

▾ Midnightotfcc_project · otfccEPSS 1.1%via NVD
CVE-2022-32386Critical· 9.8
4y ago

Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.

Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.

▾ Midnighttendacn · ac23_ac2100_firmwareEPSS 10%via NVD
CVE-2022-32385Critical· 9.8
4y ago

Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).

Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).

▾ Midnighttendacn · ac23_ac2100_firmwareEPSS 2.0%via NVD
CVE-2022-32384High· 8.8
4y ago

Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the security_5g parameter in the function formWifiBasicSet.

Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the security_5g parameter in the function formWifiBasicSet.

▾ Twilighttendacn · ac23_ac2100_firmwareEPSS 0.60%via NVD
CVE-2022-29641High· 7.5
4y ago

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules

TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Den…

▾ Twilighttotolink · a3100r_firmwareEPSS 1.2%via NVD
CVE-2022-26988High· 7.8
4y ago

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.

▾ Twilighttp-link · tl-wdr7660_firmwareEPSS 1.4%via NVD
CVE-2022-26987High· 7.8
4y ago

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.

▾ Twilighttp-link · tl-wdr7660_firmwareEPSS 1.4%via NVD
CVE-2022-0995High· 7.8CISA KEVPoC
4y ago

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a …

▾ Abyssallinux · linux_kernelEPSS 8.8%via NVD
CVE-2018-25032High· 7.5PoC
4y ago

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

▾ Midnightnokogiri · nokogiriEPSS 52%via NVD
CVE-2022-27666High· 7.8PoC
4y ago

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privileg…

▾ Midnightredhat · virtualizationEPSS 5.5%via NVD
CVE-2021-4090High· 7.1
4y ago

An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel

An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege…

▾ Twilightlinux · linux_kernelEPSS 0.34%via NVD
CVE-2022-22899Medium· 5.5
4y ago

Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.

Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.

▾ Sunlitcoreftp · core_ftpEPSS 0.87%via NVD
CVE-2022-24031High· 8.2
4y ago

An issue was discovered in NvmExpressDxe in Insyde InsydeH2O with kernel 5.1 through 5.5

An issue was discovered in NvmExpressDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalati…

▾ Twilightinsyde · insydeh2oEPSS 0.28%via NVD
CVE-2022-24030High· 7.5
4y ago

An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 through 5.5

An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulnerability allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating …

▾ Twilightinsyde · insydeh2oEPSS 0.30%via NVD
CVE-2021-43615High· 8.2
4y ago

An issue was discovered in HddPassword in Insyde InsydeH2O with kernel 5.1 before 05.16.23, 5.2 before 05.26.23, 5.3 before 05.35.23, 5.4 before 05.43.22, and 5.5 before 05.51.22

An issue was discovered in HddPassword in Insyde InsydeH2O with kernel 5.1 before 05.16.23, 5.2 before 05.26.23, 5.3 before 05.35.23, 5.4 before 05.43.22, and 5.5 before 05.51.22. An SMM memory corruption vulnerability allows an attacker…

▾ Twilightinsyde · insydeh2oEPSS 0.29%via NVD
CVE-2021-42554High· 8.2
4y ago

An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51

An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory co…

▾ Twilightinsyde · insydeh2oEPSS 0.33%via NVD
CVE-2021-42059Medium· 6.7
4y ago

An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05.26.41, Kernel 5.3 before 05.35.41, and Kernel 5.4 before 05.42.20

An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05.26.41, Kernel 5.3 before 05.35.41, and Kernel 5.4 before 05.42.20. A stack-based buffer overflow leads toarbitrary c…

▾ Sunlitinsyde · insydeh2oEPSS 0.35%via NVD
CVE-2021-43522High· 7.5
4y ago

An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 2021-11-08, 5.2 through 2021-11-08, and 5.3 through 2021-11-08

An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 2021-11-08, 5.2 through 2021-11-08, and 5.3 through 2021-11-08. A StorageSecurityCommandDxe SMM memory corruption vulnerability allows an attacker to write fixed or pred…

▾ Twilightinsyde · insydeh2oEPSS 0.26%via NVD
CVE-2021-4034High· 7.8CISA KEVPoC
4y ago

A local privilege escalation vulnerability was found on polkit's pkexec utility

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current …

▾ Abyssalpolkit_project · polkitEPSS 94%via NVD
CVE-2022-21882High· 7.0CISA KEV0dayPoC
4y ago

Win32k Elevation of Privilege Vulnerability

Win32k Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1809EPSS 59%via NVD
CVE-2021-45971High· 8.2
4y ago

An issue was discovered in SdHostDriver in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25

An issue was discovered in SdHostDriver in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mod…

▾ Twilightinsyde · insydeh2oEPSS 0.28%via NVD
CVE-2021-45970High· 8.2
4y ago

An issue was discovered in IdeBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25

An issue was discovered in IdeBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) …

▾ Twilightinsyde · insydeh2oEPSS 0.33%via NVD
CWE-787 vulnerabilities (CVEs) — page 25 · VulnSea