| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44840 | Hig | 0.51 | 7.8 | 0.00 | Aug 22, 2023 | Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c. | ||
| CVE-2022-44729 | Hig | 0.39 | 7.1 | 0.01 | Aug 22, 2023 | Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in… | ||
| CVE-2022-43358 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS). | ||
| CVE-2022-43357 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2. | ||
| CVE-2022-34038 | Hig | 0.42 | 7.5 | 0.01 | Aug 22, 2023 | Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability. | ||
| CVE-2022-28073 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0. | ||
| CVE-2022-28072 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0. | ||
| CVE-2022-28071 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | A use after free in r_reg_get_name_idx function in radare2 5.4.2 and 5.4.0. | ||
| CVE-2022-28070 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0. | ||
| CVE-2022-28069 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0. | ||
| CVE-2022-28068 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0. | ||
| CVE-2022-26592 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2023 | Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function. | ||
| CVE-2022-25024 | Hig | 0.42 | 7.5 | 0.01 | Aug 22, 2023 | The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service. | ||
| CVE-2021-46174 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37. | ||
| CVE-2021-40265 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2023 | A heap overflow bug exists FreeImage before 1.18.0 via ofLoad function in PluginJPEG.cpp. | ||
| CVE-2021-40263 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2023 | A heap overflow vulnerability in FreeImage 1.18.0 via the ofLoad function in PluginTIFF.cpp. | ||
| CVE-2021-40211 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | An issue was discovered with ImageMagick 7.1.0-4 via Division by zero in function ReadEnhMetaFile of coders/emf.c. | ||
| CVE-2021-35309 | Hig | 0.49 | 7.5 | 0.00 | Aug 22, 2023 | An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks. | ||
| CVE-2021-34193 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs. | ||
| CVE-2021-32422 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | dpic 2021.01.01 has a Global buffer overflow in theyylex() function in main.c and reads out of the bound array. | ||
| CVE-2021-32421 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | dpic 2021.01.01 has a Heap Use-After-Free in thedeletestringbox() function in dpic.y. | ||
| CVE-2021-32420 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y. | ||
| CVE-2021-30047 | Hig | 0.49 | 7.5 | 0.03 | Aug 22, 2023 | VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed. | ||
| CVE-2021-29390 | Hig | 0.46 | 7.1 | 0.01 | Aug 22, 2023 | libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c. | ||
| CVE-2020-35342 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak. | ||
| CVE-2020-26652 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service. | ||
| CVE-2020-25887 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2023 | Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file. | ||
| CVE-2020-24295 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2023 | Buffer Overflow vulnerability in PSDParser.cpp::ReadImageLine() in FreeImage 3.19.0 [r1859] allows remote attackers to ru narbitrary code via use of crafted psd file. | ||
| CVE-2020-24293 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2023 | Buffer Overflow vulnerability in psdThumbnail::Read in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted psd file. | ||
| CVE-2020-24292 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2023 | Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file. | ||
| CVE-2020-23804 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input. | ||
| CVE-2020-23793 | Hig | 0.56 | 8.6 | 0.01 | Aug 22, 2023 | An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects. | ||
| CVE-2020-22570 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command. | ||
| CVE-2020-22219 | Hig | 0.51 | 7.8 | 0.01 | Aug 22, 2023 | Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder. | ||
| CVE-2020-22218 | Hig | 0.00 | 7.5 | 0.01 | Aug 22, 2023 | An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory. | ||
| CVE-2020-21890 | Hig | 0.51 | 7.8 | 0.01 | Aug 22, 2023 | Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document. | ||
| CVE-2020-21724 | Hig | 0.51 | 7.8 | 0.00 | Aug 22, 2023 | Buffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run arbitrary code via opening of crafted ogg file. | ||
| CVE-2020-21722 | Hig | 0.51 | 7.8 | 0.01 | Aug 22, 2023 | Buffer Overflow vulnerability in oggvideotools 0.9.1 allows remote attackers to run arbitrary code via opening of crafted ogg file. | ||
| CVE-2020-21699 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests. | ||
| CVE-2020-21428 | Hig | 0.51 | 7.8 | 0.00 | Aug 22, 2023 | Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file. | ||
| CVE-2020-21427 | Hig | 0.51 | 7.8 | 0.01 | Aug 22, 2023 | Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file. | ||
| CVE-2020-21426 | Hig | 0.51 | 7.8 | 0.00 | Aug 22, 2023 | Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file. | ||
| CVE-2020-20813 | Hig | 0.49 | 7.5 | 0.01 | Aug 22, 2023 | Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet. | ||
| CVE-2020-19726 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2023 | An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service. | ||
| CVE-2020-19725 | Hig | 0.51 | 7.8 | 0.01 | Aug 22, 2023 | There is a use-after-free vulnerability in file pdd_simplifier.cpp in Z3 before 4.8.8. It occurs when the solver attempt to simplify the constraints and causes unexpected memory access. It can cause segmentation faults or arbitrary code execution. | ||
| CVE-2020-18831 | Hig | 0.51 | 7.8 | 0.01 | Aug 22, 2023 | Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. | ||
| CVE-2020-18494 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2023 | Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file. | ||
| CVE-2020-18232 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2023 | Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file. | ||
| CVE-2023-25914 | Hig | 0.57 | 8.8 | 0.01 | Aug 21, 2023 | Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise. | ||
| CVE-2023-25913 | Hig | 0.49 | 7.5 | 0.01 | Aug 21, 2023 | Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information. |
- risk 0.51cvss 7.8epss 0.00
Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c.
- risk 0.39cvss 7.1epss 0.01
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in…
- risk 0.49cvss 7.5epss 0.01
Stack overflow vulnerability in ast_selectors.cpp: in function Sass::ComplexSelector::has_placeholder in libsass:3.6.5-8-g210218, which can be exploited by attackers to cause a denial of service (DoS).
- risk 0.49cvss 7.5epss 0.01
Stack overflow vulnerability in ast_selectors.cpp in function Sass::CompoundSelector::has_real_parent_ref in libsass:3.6.5-8-g210218, which can be exploited by attackers to causea denial of service (DoS). Also affects the command line driver for libsass, sassc 3.6.2.
- risk 0.42cvss 7.5epss 0.01
Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability.
- risk 0.00cvss 7.5epss 0.01
A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0.
- risk 0.00cvss 7.5epss 0.01
A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0.
- risk 0.00cvss 7.5epss 0.01
A use after free in r_reg_get_name_idx function in radare2 5.4.2 and 5.4.0.
- risk 0.00cvss 7.5epss 0.01
A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0.
- risk 0.00cvss 7.5epss 0.01
A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0.
- risk 0.00cvss 7.5epss 0.01
A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0.
- risk 0.57cvss 8.8epss 0.01
Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function.
- risk 0.42cvss 7.5epss 0.01
The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.
- risk 0.49cvss 7.5epss 0.01
Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.
- risk 0.57cvss 8.8epss 0.01
A heap overflow bug exists FreeImage before 1.18.0 via ofLoad function in PluginJPEG.cpp.
- risk 0.57cvss 8.8epss 0.01
A heap overflow vulnerability in FreeImage 1.18.0 via the ofLoad function in PluginTIFF.cpp.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered with ImageMagick 7.1.0-4 via Division by zero in function ReadEnhMetaFile of coders/emf.c.
- risk 0.49cvss 7.5epss 0.00
An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.
- risk 0.49cvss 7.5epss 0.01
Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.
- risk 0.00cvss 7.5epss 0.01
dpic 2021.01.01 has a Global buffer overflow in theyylex() function in main.c and reads out of the bound array.
- risk 0.00cvss 7.5epss 0.01
dpic 2021.01.01 has a Heap Use-After-Free in thedeletestringbox() function in dpic.y.
- risk 0.00cvss 7.5epss 0.01
dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y.
- risk 0.49cvss 7.5epss 0.03
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
- risk 0.46cvss 7.1epss 0.01
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
- risk 0.49cvss 7.5epss 0.01
GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.
- risk 0.57cvss 8.8epss 0.01
Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.
- risk 0.57cvss 8.8epss 0.01
Buffer Overflow vulnerability in PSDParser.cpp::ReadImageLine() in FreeImage 3.19.0 [r1859] allows remote attackers to ru narbitrary code via use of crafted psd file.
- risk 0.57cvss 8.8epss 0.01
Buffer Overflow vulnerability in psdThumbnail::Read in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted psd file.
- risk 0.57cvss 8.8epss 0.01
Buffer Overflow vulnerability in load function in PluginICO.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to run arbitrary code via opening of crafted ico file.
- risk 0.49cvss 7.5epss 0.01
Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
- risk 0.56cvss 8.6epss 0.01
An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects.
- risk 0.49cvss 7.5epss 0.01
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.
- risk 0.51cvss 7.8epss 0.01
Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder.
- risk 0.00cvss 7.5epss 0.01
An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.
- risk 0.51cvss 7.8epss 0.01
Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document.
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run arbitrary code via opening of crafted ogg file.
- risk 0.51cvss 7.8epss 0.01
Buffer Overflow vulnerability in oggvideotools 0.9.1 allows remote attackers to run arbitrary code via opening of crafted ogg file.
- risk 0.49cvss 7.5epss 0.01
The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests.
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
- risk 0.51cvss 7.8epss 0.01
Buffer Overflow vulnerability in function LoadPixelDataRLE8 in PluginBMP.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
- risk 0.51cvss 7.8epss 0.00
Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
- risk 0.49cvss 7.5epss 0.01
Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
- risk 0.51cvss 7.8epss 0.01
There is a use-after-free vulnerability in file pdd_simplifier.cpp in Z3 before 4.8.8. It occurs when the solver attempt to simplify the constraints and causes unexpected memory access. It can cause segmentation faults or arbitrary code execution.
- risk 0.51cvss 7.8epss 0.01
Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file.
- risk 0.57cvss 8.8epss 0.01
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.
- risk 0.57cvss 8.8epss 0.01
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.
- risk 0.57cvss 8.8epss 0.01
Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise.
- risk 0.49cvss 7.5epss 0.01
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.