Vulnerabilities (CVE)

Filtered by CWE-787
Total 6464 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-24453 3 Adobe, Apple, Microsoft 3 Indesign, Macos, Windows 2025-04-28 N/A 7.8 HIGH
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2025-24452 3 Adobe, Apple, Microsoft 3 Indesign, Macos, Windows 2025-04-28 N/A 7.8 HIGH
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2025-27169 3 Adobe, Apple, Microsoft 3 Illustrator, Macos, Windows 2025-04-28 N/A 7.8 HIGH
Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2022-36337 1 Insyde 1 Kernel 2025-04-25 N/A 8.2 HIGH
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Control of a UEFI variable under the OS can cause this overflow when read by BIOS code.
CVE-2022-44789 3 Artifex, Debian, Fedoraproject 3 Mujs, Debian Linux, Fedora 2025-04-25 N/A 8.8 HIGH
A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.
CVE-2022-44260 1 Totolink 2 Lr350, Lr350 Firmware 2025-04-25 N/A 8.8 HIGH
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function.
CVE-2022-44259 1 Totolink 2 Lr350, Lr350 Firmware 2025-04-25 N/A 8.8 HIGH
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.
CVE-2022-44258 1 Totolink 2 Lr350, Lr350 Firmware 2025-04-25 N/A 8.8 HIGH
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.
CVE-2022-44257 1 Totolink 2 Lr350, Lr350 Firmware 2025-04-25 N/A 8.8 HIGH
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.
CVE-2022-44256 1 Totolink 2 Nr1800x, Nr1800x Firmware 2025-04-25 N/A 8.8 HIGH
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.
CVE-2022-44254 1 Totolink 2 Lr350, Lr350 Firmware 2025-04-25 N/A 8.8 HIGH
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.
CVE-2022-44253 1 Totolink 2 Lr350, Lr350 Firmware 2025-04-25 N/A 8.8 HIGH
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.
CVE-2021-45985 1 Lua 1 Lua 2025-04-25 N/A 7.5 HIGH
In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.
CVE-2024-20092 2 Google, Mediatek 17 Android, Mt6761, Mt6765 and 14 more 2025-04-25 N/A 7.8 HIGH
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09028313; Issue ID: MSV-1700.
CVE-2020-29367 1 Blosc 1 C-blosc2 2025-04-25 9.3 HIGH 7.8 HIGH
blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.
CVE-2023-32837 2 Google, Mediatek 7 Android, Mt6883, Mt6885 and 4 more 2025-04-25 N/A 7.8 HIGH
In video, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08235273; Issue ID: ALPS08250357.
CVE-2023-32832 2 Google, Mediatek 10 Android, Mt6883, Mt6885 and 7 more 2025-04-25 N/A 7.0 HIGH
In video, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08235273; Issue ID: ALPS08235273.
CVE-2022-45202 1 Gpac 1 Gpac 2025-04-25 N/A 7.8 HIGH
GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isomedia/box_code_3gpp.c.
CVE-2022-45337 1 Tenda 2 Tx9 Pro, Tx9 Pro Firmware 2025-04-24 N/A 7.5 HIGH
Tenda TX9 Pro v22.03.02.10 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.
CVE-2022-45332 1 Gnu 1 Libredwg 2025-04-24 N/A 7.8 HIGH
LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.