Search Results (20840 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-4276 1 Littlecms 1 Little Cms Color Engine 2024-08-06 N/A
Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIFF image to the tiffdiff utility.
CVE-2013-4357 5 Canonical, Debian, Eglibc and 2 more 5 Ubuntu Linux, Debian Linux, Eglibc and 2 more 2024-08-06 7.5 High
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
CVE-2013-4365 4 Apache, Debian, Opensuse and 1 more 6 Http Server, Mod Fcgid, Debian Linux and 3 more 2024-08-06 N/A
Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.
CVE-2013-4282 2 Redhat, Spice Project 3 Enterprise Linux, Enterprise Virtualization, Spice 2024-08-06 N/A
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
CVE-2013-4344 4 Canonical, Opensuse, Qemu and 1 more 8 Ubuntu Linux, Opensuse, Qemu and 5 more 2024-08-06 N/A
Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.
CVE-2013-4289 1 Uclouvain 1 Openjpeg 2024-08-06 N/A
Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified impact and vectors, which trigger a heap-based buffer overflow.
CVE-2013-4243 3 Debian, Libtiff, Redhat 3 Debian Linux, Libtiff, Enterprise Linux 2024-08-06 N/A
Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted height and width values in a GIF image.
CVE-2024-28283 2024-08-06 6.7 Medium
There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before, leading to remote code execution.
CVE-2024-21479 1 Qualcomm 90 Ar8035 Firmware, Fastconnect 6700 Firmware, Fastconnect 6800 Firmware and 87 more 2024-08-06 7.5 High
Transient DOS during music playback of ALAC content.
CVE-2024-21459 1 Qualcomm 172 Ar8035 Firmware, Ar9380 Firmware, Csr8811 Firmware and 169 more 2024-08-06 6.5 Medium
Information disclosure while handling beacon or probe response frame in STA.
CVE-2024-21467 1 Qualcomm 126 Csr8811 Firmware, Fastconnect 6800 Firmware, Fastconnect 6900 Firmware and 123 more 2024-08-06 6.5 Medium
Information disclosure while handling beacon probe frame during scan entry generation in client side.
CVE-2024-33014 1 Qualcomm 304 315 5g Iot Modem Firmware, Apq8064au Firmware, Aqt1000 Firmware and 301 more 2024-08-06 7.5 High
Transient DOS while parsing ESP IE from beacon/probe response frame.
CVE-2024-33025 1 Qualcomm 166 Csr8811 Firmware, Fastconnect 6800 Firmware, Fastconnect 6900 Firmware and 163 more 2024-08-06 7.5 High
Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.
CVE-2024-33026 1 Qualcomm 164 Ar8035 Firmware, Csr8811 Firmware, Fastconnect 6700 Firmware and 161 more 2024-08-06 7.5 High
Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.
CVE-2024-7055 2024-08-06 6.3 Medium
A vulnerability was found in FFmpeg up to 7.0.1. It has been classified as critical. This affects the function pnm_decode_frame in the library /libavcodec/pnmdec.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0.2 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-273651.
CVE-2024-33012 1 Qualcomm 240 Ar8035 Firmware, Ar9380 Firmware, Csr8811 Firmware and 237 more 2024-08-06 7.5 High
Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.
CVE-2024-23353 1 Qualcomm 212 315 5g Iot Modem Firmware, 9205 Lte Modem Firmware, 9206 Lte Modem Firmware and 209 more 2024-08-06 7.5 High
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
CVE-2022-48844 1 Linux 1 Linux Kernel 2024-08-03 5.5 Medium
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix leaking sent_cmd skb sent_cmd memory is not freed before freeing hci_dev causing it to leak it contents.
CVE-2024-38481 1 Dell 1 Emc Idrac Service Module 2024-08-02 4.8 Medium
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
CVE-2024-7331 1 Totolink 2 A3300r, A3300r Firmware 2024-08-01 8.8 High
A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273254 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.