Filtered by CWE-125
Total 7200 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-31881 1 Siemens 16 Apogee Modular Building Controller, Apogee Modular Building Controller Firmware, Apogee Modular Equiment Controller and 13 more 2024-10-08 7.1 High
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). When processing a DHCP OFFER message, the DHCP client application does not validate the length of the Vendor option(s), leading to Denial-of-Service conditions. (FSMD-2021-0008)
CVE-2024-44912 1 Nasa 1 Cryptolib 2024-10-07 7.5 High
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c).
CVE-2024-44911 1 Nasa 1 Cryptolib 2024-10-07 7.5 High
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_aos.c).
CVE-2024-44910 1 Nasa 1 Cryptolib 2024-10-07 7.5 High
NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).
CVE-2023-23418 1 Microsoft 2 Windows 11 22h2, Windows 11 22h2 2024-10-04 7.8 High
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2023-21819 1 Microsoft 11 Windows 10 1809, Windows 10 20h2, Windows 10 20h2 and 8 more 2024-10-04 7.5 High
Windows Secure Channel Denial of Service Vulnerability
CVE-2023-21776 1 Microsoft 21 Windows 10, Windows 10 1507, Windows 10 1607 and 18 more 2024-10-04 5.5 Medium
Windows Kernel Information Disclosure Vulnerability
CVE-2023-24900 1 Microsoft 21 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 18 more 2024-10-04 5.9 Medium
Windows NTLM Security Support Provider Information Disclosure Vulnerability
CVE-2021-29390 3 Fedoraproject, Libjpeg-turbo, Redhat 3 Fedora, Libjpeg-turbo, Enterprise Linux 2024-10-04 7.1 High
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
CVE-2022-1304 3 E2fsprogs Project, Fedoraproject, Redhat 3 E2fsprogs, Fedora, Enterprise Linux 2024-10-04 7.8 High
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
CVE-2024-0116 2024-10-04 4.9 Medium
NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing a shared memory region while it is in use. A successful exploit of this vulnerability may lead to denial of service.
CVE-2024-41595 1 Draytek 1 Vigor3910 Firmware 2024-10-04 8 High
DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bounds checks on read and write operations.
CVE-2024-8159 2024-10-04 6.4 Medium
Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of the FarDisk.sys driver.
CVE-2023-30760 1 Intel 2 Realsense 450 Fa, Realsense 450 Fa Firmware 2024-10-03 3.3 Low
Out-of-bounds read in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-22217 3 C-ares, Debian, Redhat 4 C-ares, Debian Linux, Enterprise Linux and 1 more 2024-10-03 5.9 Medium
Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.
CVE-2023-38668 1 Nasm 1 Netwide Assembler 2024-10-03 5.5 Medium
Stack-based buffer over-read in disasm in nasm 2.16 allows attackers to cause a denial of service (crash).
CVE-2020-22218 2 Libssh2, Redhat 2 Libssh2, Enterprise Linux 2024-10-03 7.5 High
An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.
CVE-2020-22628 1 Libraw 1 Libraw 2024-10-03 6.5 Medium
Buffer Overflow vulnerability in LibRaw::stretch() function in libraw\src\postprocessing\aspect_ratio.cpp.
CVE-2021-32292 1 Json-c Project 1 Json-c 2024-10-03 9.8 Critical
An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
CVE-2024-24923 1 Siemens 1 Simcenter Femap 2024-10-03 7.8 High
A vulnerability has been identified in Simcenter Femap (All versions < V2401.0000), Simcenter Femap (All versions < V2306.0001). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted Catia MODEL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-22055)