Vulnerabilities (CVE)

Filtered by CWE-787
Total 10481 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-23082 1 Kodi 1 Kodi 2024-01-23 N/A 4.6 MEDIUM
A heap buffer overflow vulnerability in Kodi Home Theater Software up to 19.5 allows attackers to cause a denial of service due to an improper length of the value passed to the offset argument.
CVE-2020-14498 1 Hms-networks 1 Ecatcher 2024-01-23 10.0 HIGH 10.0 CRITICAL
HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
CVE-2024-0517 2 Fedoraproject, Google 2 Fedora, Chrome 2024-01-22 N/A 8.8 HIGH
Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2021-3826 2 Fedoraproject, Gnu 2 Fedora, Gcc 2024-01-22 N/A 6.5 MEDIUM
Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled symbol.
CVE-2023-5686 2 Fedoraproject, Radare 2 Fedora, Radare2 2024-01-21 N/A 8.8 HIGH
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
CVE-2023-4322 2 Fedoraproject, Radare 2 Fedora, Radare2 2024-01-21 N/A 9.8 CRITICAL
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
CVE-2023-51742 1 Skyworthdigital 2 Cm5100, Cm5100 Firmware 2024-01-20 N/A 7.5 HIGH
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Add Downstream Frequency parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform a Denial of Service (DoS) attack on the targeted system.
CVE-2023-51743 1 Skyworthdigital 2 Cm5100, Cm5100 Firmware 2024-01-20 N/A 7.5 HIGH
This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Set Upstream Channel ID (UCID) parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable targeted system. Successful exploitation of this vulnerability could allow the attacker to perform a Denial of Service (DoS) attack on the targeted system.
CVE-2023-52110 1 Huawei 1 Harmonyos 2024-01-19 N/A 7.5 HIGH
The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.
CVE-2023-48351 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-01-19 N/A 5.5 MEDIUM
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVE-2023-48350 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-01-19 N/A 5.5 MEDIUM
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVE-2023-48349 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-01-19 N/A 5.5 MEDIUM
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
CVE-2023-48348 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-01-19 N/A 5.5 MEDIUM
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVE-2023-48343 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-01-19 N/A 5.5 MEDIUM
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVE-2023-48342 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-01-19 N/A 4.4 MEDIUM
In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
CVE-2023-48340 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2024-01-19 N/A 5.5 MEDIUM
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with no additional execution privileges needed
CVE-2023-21255 2 Debian, Google 2 Debian Linux, Android 2024-01-19 N/A 7.8 HIGH
In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-31031 1 Nvidia 2 Dgx A100, Dgx A100 Firmware 2024-01-19 N/A 7.8 HIGH
NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering.
CVE-2023-49992 1 Espeak-ng 1 Espeak-ng 2024-01-19 N/A 5.3 MEDIUM
Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.
CVE-2023-49991 1 Espeak-ng 1 Espeak-ng 2024-01-19 N/A 5.3 MEDIUM
Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.