Vulnerabilities (CVE)

Filtered by CWE-120
Total 721 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-4260 1 Zephyrproject 1 Zephyr 2025-02-13 N/A 6.3 MEDIUM
Potential off-by-one buffer overflow vulnerability in the Zephyr fuse file system.
CVE-2023-4163 1 Broadcom 1 Fabric Operating System 2025-02-13 N/A 4.4 MEDIUM
In Brocade Fabric OS before v9.2.0a, a local authenticated privileged user can trigger a buffer overflow condition, leading to a kernel panic with large input to buffers in the portcfgfportbuffers command.
CVE-2023-31431 1 Broadcom 1 Brocade Fabric Operating System 2025-02-13 N/A 5.5 MEDIUM
A buffer overflow vulnerability in “diagstatus” command in Brocade Fabric OS before Brocade Fabric v9.2.0 and v9.1.1c could allow an authenticated user to crash the Brocade Fabric OS switch leading to a denial of service.
CVE-2023-31430 1 Broadcom 1 Brocade Fabric Operating System 2025-02-13 N/A 5.5 MEDIUM
A buffer overflow vulnerability in “secpolicydelete” command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0 could allow an authenticated privileged user to crash the Brocade Fabric OS switch leading to a denial of service.
CVE-2024-0144 2025-02-12 N/A 6.8 MEDIUM
NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a buffer overflow issue by means of a specially crafted JPEG2000 file. A successful exploit of this vulnerability might lead to data tampering.
CVE-2020-24736 1 Ghost 1 Sqlite3 2025-02-11 N/A 5.5 MEDIUM
Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script.
CVE-2024-35106 2025-02-11 N/A 4.6 MEDIUM
NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability allows attackers to cause a Denial of Service (DoS) or potentially arbitrary code execution via a crafted POST request.
CVE-2025-24956 2025-02-11 N/A 6.2 MEDIUM
A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a buffer overflow that leads to memory corruption.
CVE-2022-47336 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-02-10 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47335 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-02-10 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47464 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-02-10 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47463 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-02-10 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47362 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-02-10 N/A 5.5 MEDIUM
In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2025-24131 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2025-02-05 N/A 6.5 MEDIUM
The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An attacker in a privileged position may be able to perform a denial-of-service.
CVE-2025-24153 1 Apple 1 Macos 2025-02-04 N/A 6.7 MEDIUM
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.
CVE-2023-2241 1 Podofo Project 1 Podofo 2025-02-04 4.3 MEDIUM 5.3 MEDIUM
A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is 535a786f124b739e3c857529cecc29e4eeb79778. It is recommended to apply a patch to fix this issue. VDB-227226 is the identifier assigned to this vulnerability.
CVE-2024-57513 2025-01-31 N/A 6.5 MEDIUM
A floating-point exception (FPE) vulnerability exists in the AP4_TfraAtom::AP4_TfraAtom function in Bento4.
CVE-2023-29932 1 Llvm 1 Llvm 2025-01-29 N/A 5.5 MEDIUM
llvm-project commit fdbc55a5 was discovered to contain a segmentation fault via the component mlir::IROperand<mlir::OpOperand.
CVE-2023-23535 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2025-01-29 N/A 5.5 MEDIUM
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, macOS Big Sur 11.7.5, iOS 15.7.4 and iPadOS 15.7.4, macOS Monterey 12.6.6, tvOS 16.4, watchOS 9.4. Processing a maliciously crafted image may result in disclosure of process memory.
CVE-2023-23494 1 Apple 2 Ipados, Iphone Os 2025-01-29 N/A 5.3 MEDIUM
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. A user in a privileged network position may be able to cause a denial-of-service.