Filtered by CWE-125
Total 7200 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-7255 1 Google 1 Chrome 2024-10-29 8.8 High
Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVE-2024-6600 2024-10-29 6.3 Medium
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on mac OS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
CVE-2024-40799 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2024-10-29 7.1 High
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Ventura 13.6.8, macOS Monterey 12.7.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing a maliciously crafted file may lead to unexpected app termination.
CVE-2024-34974 1 Tenda 1 Ac18 2024-10-29 8.2 High
Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.
CVE-2024-34950 1 D-link 1 Dir-822 2024-10-29 7.5 High
D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.
CVE-2024-34200 1 Totolink 1 Cp450 2024-10-29 8.8 High
TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.
CVE-2024-31714 1 Waxlab 1 Wax 2024-10-29 7.5 High
Buffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the Lua library component.
CVE-2022-3447 1 Google 2 Android, Chrome 2024-10-29 4.3 Medium
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
CVE-1999-0029 1 Sgi 1 Irix 2024-10-29 8.4 High
root privileges via buffer overflow in ordist command on SGI IRIX systems.
CVE-2021-40812 1 Libgd 1 Libgd 2024-10-29 6.5 Medium
The GD Graphics Library (aka LibGD) through 2.3.2 has an out-of-bounds read because of the lack of certain gdGetBuf and gdPutBuf return value checks.
CVE-1999-0022 6 Bsdi, Freebsd, Hp and 3 more 7 Bsd Os, Freebsd, Hp-ux and 4 more 2024-10-29 7.8 High
Local user gains root privileges via buffer overflow in rdist, via expstr() function.
CVE-1999-0006 1 Qualcomm 1 Qpopper 2024-10-29 9.8 Critical
Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.
CVE-2024-47021 1 Google 1 Android 2024-10-28 5.1 Medium
In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-0794 2024-10-28 9.8 Critical
Certain HP LaserJet Pro, HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to Remote Code Execution due to buffer overflow when rendering fonts embedded in a PDF file.
CVE-2024-48208 1 Pureftpd 1 Pure-ftpd 2024-10-28 8.6 High
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
CVE-2024-28640 1 Totolink 2 A7000r Firmware, X5000r Firmware 2024-10-28 7.5 High
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.
CVE-2024-28578 1 Freeimage Project 1 Freeimage 2024-10-28 8.4 High
Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Load() function when reading images in RAS format.
CVE-2024-28537 1 Tenda 1 Ac18 Firmware 2024-10-28 9.8 Critical
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
CVE-2023-47456 1 Tenda 2 Ax1806, Ax1806 Firmware 2024-10-28 9.1 Critical
Tenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessRepeat.
CVE-2020-23909 1 Advancemame 1 Advancemame 2024-10-28 7.1 High
Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1.