Vulnerabilities (CVE)

Filtered by CWE-124
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-34351 1 Intel 1 Performance Counter Monitor 2024-10-29 N/A 7.5 HIGH
Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access.
CVE-2024-33763 2024-07-03 N/A 7.5 HIGH
lunasvg v2.3.9 was discovered to contain a stack-buffer-underflow at lunasvg/source/layoutcontext.cpp.
CVE-2023-31130 2 C-ares Project, Fedoraproject 2 C-ares, Fedora 2024-06-10 N/A 6.4 MEDIUM
c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an address via ares_set_sortlist(). However, users may externally use ares_inet_net_pton() for other purposes and thus be vulnerable to more severe issues. This issue has been fixed in 1.19.1.
CVE-2022-33896 1 Hancom 1 Hancom Office 2020 2024-02-04 N/A 7.8 HIGH
A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.
CVE-2021-36064 1 Adobe 1 Xmp Toolkit Software Development Kit 2024-02-04 9.3 HIGH 7.8 HIGH
XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.