Vulnerabilities (CVE)

Filtered by CWE-120
Total 733 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-52103 1 Huawei 2 Emui, Harmonyos 2024-11-21 N/A 9.8 CRITICAL
Buffer overflow vulnerability in the FLP module. Successful exploitation of this vulnerability may cause out-of-bounds read.
CVE-2023-51885 1 Ctan 1 Mathtex 2024-11-21 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via the length of the LaTeX string component.
CVE-2023-51434 1 Hihonor 1 Magic Ui 2024-11-21 N/A 9.3 CRITICAL
Some Honor products are affected by buffer overflow vulnerability, successful exploitation could cause code execution.
CVE-2023-50986 1 Tenda 2 I29, I29 Firmware 2024-11-21 N/A 9.8 CRITICAL
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.
CVE-2023-50628 1 Libming 1 Libming 2024-11-21 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in libming version 0.4.8, allows attackers to execute arbitrary code and obtain sensitive information via parser.c component.
CVE-2023-50469 1 Szlbt 2 Lbt-t300-t310, Lbt-t300-t310 Firmware 2024-11-21 N/A 9.8 CRITICAL
Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEncrypType parameter at /apply.cgi.
CVE-2023-50245 1 Afichet 1 Openexr Viewer 2024-11-21 N/A 9.8 CRITICAL
OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overflow vulnerability. This issue is fixed in version 0.6.1.
CVE-2023-50044 1 Cesanta 1 Mjs 2024-11-21 N/A 9.8 CRITICAL
Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.
CVE-2023-4041 1 Silabs 1 Gecko Bootloader 2024-11-21 N/A 9.8 CRITICAL
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This issue affects "Standalone" and "Application" versions of Gecko Bootloader.
CVE-2023-49208 1 Glewlwyd Sso Server Project 1 Glewlwyd Sso Server 2024-11-21 N/A 9.8 CRITICAL
scheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation in webauthn registration.
CVE-2023-45929 2024-11-21 N/A 9.1 CRITICAL
S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().
CVE-2023-45797 1 Dreamsecurity 1 Magicline 4.0 2024-11-21 N/A 9.8 CRITICAL
A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotely execute code.
CVE-2023-45616 2 Arubanetworks, Hp 2 Arubaos, Instantos 2024-11-21 N/A 9.8 CRITICAL
There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVE-2023-45615 2 Arubanetworks, Hp 2 Arubaos, Instantos 2024-11-21 N/A 9.8 CRITICAL
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVE-2023-45614 2 Arubanetworks, Hp 2 Arubaos, Instantos 2024-11-21 N/A 9.8 CRITICAL
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVE-2023-45481 1 Tenda 2 Ac10, Ac10 Firmware 2024-11-21 N/A 9.8 CRITICAL
Tenda AC10 version US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the firewallEn parameter in the function SetFirewallCfg.
CVE-2023-45199 1 Arm 1 Mbed Tls 2024-11-21 N/A 9.8 CRITICAL
Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
CVE-2023-43504 1 Siemens 1 Comos 2024-11-21 N/A 9.6 CRITICAL
A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validation service in affected application is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an attacker to execute arbitrary code on the target system or cause denial of service condition.
CVE-2023-43131 1 Maxiguvenlik 1 General Device Manager 2024-11-21 N/A 9.8 CRITICAL
General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.
CVE-2023-42320 1 Tenda 2 Ac10, Ac10 Firmware 2024-11-21 N/A 9.8 CRITICAL
Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.