Vulnerabilities (CVE)

Filtered by CWE-120
Total 710 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-22924 1 Zyxel 2 Nbg-418n, Nbg-418n Firmware 2024-11-21 N/A 4.9 MEDIUM
A buffer overflow vulnerability in the Zyxel NBG-418N v2 firmware versions prior to V1.00(AARP.14)C0 could allow a remote authenticated attacker with administrator privileges to cause denial-of-service (DoS) conditions by executing crafted CLI commands on a vulnerable device.
CVE-2023-22745 1 Tpm2 Software Stack Project 1 Tpm2 Software Stack 2024-11-21 N/A 6.4 MEDIUM
tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In affected versions `Tss2_RC_SetHandler` and `Tss2_RC_Decode` both index into `layer_handler` with an 8 bit layer number, but the array only has `TPM2_ERROR_TSS2_RC_LAYER_COUNT` entries, so trying to add a handler for higher-numbered layers or decode a response code with such a layer number reads/writes past the end of the buffer. This Buffer overrun, could result in arbitrary code execution. An example attack would be a MiTM bus attack that returns 0xFFFFFFFF for the RC. Given the common use case of TPM modules an attacker must have local access to the target machine with local system privileges which allows access to the TPM system. Usually TPM access requires administrative privilege.
CVE-2023-22384 1 Qualcomm 18 Qca6574au, Qca6574au Firmware, Qca6696 and 15 more 2024-11-21 N/A 6.7 MEDIUM
Memory Corruption in VR Service while sending data using Fast Message Queue (FMQ).
CVE-2023-21649 1 Qualcomm 130 Apq8096au, Apq8096au Firmware, Aqt1000 and 127 more 2024-11-21 N/A 6.7 MEDIUM
Memory corruption in WLAN while running doDriverCmd for an unspecific command.
CVE-2023-21640 1 Qualcomm 12 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 9 more 2024-11-21 N/A 6.7 MEDIUM
Memory corruption in Linux when the file upload API is called with parameters having large buffer.
CVE-2023-21639 1 Qualcomm 44 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 41 more 2024-11-21 N/A 6.7 MEDIUM
Memory corruption in Audio while processing sva_model_serializer using memory size passed by HIDL client.
CVE-2023-21635 1 Qualcomm 98 Aqt1000, Aqt1000 Firmware, Csrb31024 and 95 more 2024-11-21 N/A 6.7 MEDIUM
Memory Corruption in Data Network Stack & Connectivity when sim gets detected on telephony.
CVE-2023-21504 1 Samsung 1 Android 2024-11-21 N/A 5.6 MEDIUM
Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
CVE-2023-21503 1 Samsung 2 Android, Exynos 2024-11-21 N/A 5.6 MEDIUM
Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
CVE-2023-21494 1 Samsung 2 Android, Exynos 2024-11-21 N/A 5.6 MEDIUM
Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
CVE-2023-21243 1 Google 1 Android 2024-11-21 N/A 5.5 MEDIUM
In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
CVE-2023-1452 1 Gpac 1 Gpac 2024-11-21 4.3 MEDIUM 5.3 MEDIUM
A vulnerability was found in GPAC 2.3-DEV-rev35-gbbca86917-master. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file filters/load_text.c. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-223297 was assigned to this vulnerability.
CVE-2023-1190 1 Imageinfo Project 1 Imageinfo 2024-11-21 4.3 MEDIUM 4.8 MEDIUM
A vulnerability was found in xiaozhuai imageinfo up to 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file imageinfo.hpp. The manipulation leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. VDB-222362 is the identifier assigned to this vulnerability.
CVE-2023-0977 3 Linux, Microsoft, Trellix 3 Linux Kernel, Windows, Agent 2024-11-21 N/A 6.7 MEDIUM
A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in the macmnsvc process memory block resulting in the service becoming unavailable.
CVE-2023-0687 1 Gnu 1 Glibc 2024-11-21 4.0 MEDIUM 4.6 MEDIUM
** DISPUTED ** A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier assigned to this vulnerability. NOTE: The real existence of this vulnerability is still doubted at the moment. The inputs that induce this vulnerability are basically addresses of the running application that is built with gmon enabled. It's basically trusted input or input that needs an actual security flaw to be compromised or controlled.
CVE-2022-4969 2024-11-21 4.3 MEDIUM 5.3 MEDIUM
A vulnerability, which was classified as critical, has been found in bwoodsend rockhopper up to 0.1.2. Affected by this issue is the function count_rows of the file rockhopper/src/ragged_array.c of the component Binary Parser. The manipulation of the argument raw leads to buffer overflow. Local access is required to approach this attack. Upgrading to version 0.2.0 is able to address this issue. The name of the patch is 1a15fad5e06ae693eb9b8908363d2c8ef455104e. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-266312.
CVE-2022-4857 1 Modbustools 1 Modbus Poll 2024-11-21 7.5 HIGH 6.3 MEDIUM
A vulnerability was found in Modbus Tools Modbus Poll up to 9.10.0 and classified as critical. Affected by this issue is some unknown functionality of the file mbpoll.exe of the component mbp File Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-217022 is the identifier assigned to this vulnerability.
CVE-2022-4856 1 Modbustools 1 Modbus Slave 2024-11-21 N/A 6.3 MEDIUM
A vulnerability has been found in Modbus Tools Modbus Slave up to 7.5.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file mbslave.exe of the component mbs File Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-217021 was assigned to this vulnerability.
CVE-2022-47990 1 Ibm 2 Aix, Vios 2024-11-21 N/A 6.2 MEDIUM
IBM AIX 7.1, 7.2, 7.3 and VIOS , 3.1 could allow a non-privileged local user to exploit a vulnerability in X11 to cause a buffer overflow that could result in a denial of service or arbitrary code execution. IBM X-Force ID: 243556.  
CVE-2022-46824 2 Apple, Jetbrains 2 Macos, Intellij Idea 2024-11-21 N/A 5.6 MEDIUM
In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.