Search Results (19034 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-29944 1 Metersphere 1 Metersphere 2025-01-29 9.8 Critical
Metersphere v1.20.20-lts-79d354a6 is vulnerable to Remote Command Execution. The system command reverse-shell can be executed at the custom code snippet function of the metersphere system workbench
CVE-2023-29696 1 H3c 2 Gr-1200w, Gr-1200w Firmware 2025-01-29 9.8 Critical
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function version_set.
CVE-2023-29693 1 H3c 2 Gr-1200w, Gr-1200w Firmware 2025-01-29 9.8 Critical
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function set_tftp_upgrad.
CVE-2023-30054 1 Totolink 2 A7100ru, A7100ru Firmware 2025-01-29 9.8 Critical
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability. An attacker can obtain a stable root shell through a specially constructed payload.
CVE-2023-30053 1 Totolink 2 A7100ru, A7100ru Firmware 2025-01-29 9.8 Critical
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.
CVE-2023-30013 1 Totolink 2 X5000r, X5000r Firmware 2025-01-29 9.8 Critical
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg. This vulnerability allows an attacker to execute arbitrary commands through the "command" parameter.
CVE-2023-31981 1 Irontec 1 Sngrep 2025-01-29 7.8 High
Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c.
CVE-2023-24958 1 Ibm 6 3948-ved, 3948-ved Firmware, 3957-vec and 3 more 2025-01-29 8.8 High
A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submit a specially crafted URL leading to privilege escalation and remote code execution. IBM X-Force ID: 246320.
CVE-2022-48239 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-01-29 4.4 Medium
In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.
CVE-2022-32885 2 Apple, Redhat 10 Ipados, Iphone Os, Macos and 7 more 2025-01-29 8.8 High
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution
CVE-2024-3900 1 Xpdfreader 1 Xpdf 2025-01-29 2.9 Low
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.
CVE-2023-27970 1 Apple 2 Ipados, Iphone Os 2025-01-29 7.8 High
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. An app may be able to execute arbitrary code with kernel privileges.
CVE-2024-4141 1 Xpdfreader 1 Xpdf 2025-01-29 2.9 Low
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.
CVE-2024-4976 1 Xpdfreader 1 Xpdf 2025-01-29 5.5 Medium
Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.
CVE-2024-2971 1 Xpdfreader 1 Xpdf 2025-01-29 2.9 Low
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file.
CVE-2023-2564 1 Scanservjs Project 1 Scanservjs 2025-01-29 10 Critical
OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.
CVE-2023-30837 1 Vyperlang 1 Vyper 2025-01-29 7.5 High
Vyper is a pythonic smart contract language for the EVM. The storage allocator does not guard against allocation overflows in versions prior to 0.3.8. An attacker can overwrite the owner variable. This issue was fixed in version 0.3.8.
CVE-2024-55194 1 Openimageio 1 Openimageio 2025-01-29 9.8 Critical
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
CVE-2023-30087 1 Cesanta 1 Mjs 2025-01-29 5.5 Medium
Buffer Overflow vulnerability found in Cesanta MJS v.1.26 allows a local attacker to cause a denial of service via the mjs_mk_string function in mjs.c.
CVE-2023-30086 2 Libtiff, Redhat 2 Libtiff, Enterprise Linux 2025-01-29 5.5 Medium
Buffer Overflow vulnerability found in Libtiff V.4.0.7 allows a local attacker to cause a denial of service via the tiffcp function in tiffcp.c.