Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-119
Total 11483 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-4330 1 Apple 1 Iphone Os 2019-01-23 9.3 HIGH 7.8 HIGH
In iOS before 11.4, a memory corruption issue exists and was addressed with improved memory handling.
CVE-2018-18820 2 Debian, Xiph 2 Debian Linux, Icecast 2019-01-23 6.8 MEDIUM 8.1 HIGH
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of service and potentially remote code execution.
CVE-2016-7576 1 Apple 1 Iphone Os 2019-01-17 9.3 HIGH 7.8 HIGH
In iOS before 9.3.3, a memory corruption issue existed in the kernel. This issue was addressed through improved memory handling.
CVE-2018-4147 2 Apple, Microsoft 5 Icloud, Iphone Os, Itunes and 2 more 2019-01-17 6.8 MEDIUM 9.8 CRITICAL
In iCloud for Windows before 7.3, Safari before 11.0.3, iTunes before 12.7.3 for Windows, and iOS before 11.2.5, multiple memory corruption issues exist and were addressed with improved memory handling.
CVE-2018-4189 1 Apple 4 Apple Tv, Iphone Os, Mac Os X and 1 more 2019-01-17 10.0 HIGH 9.8 CRITICAL
In iOS before 11.2.5, macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, watchOS before 4.2.2, and tvOS before 11.2.5, a memory corruption issue exists and was addressed with improved memory handling.
CVE-2018-12326 1 Redislabs 1 Redis 2019-01-17 4.6 MEDIUM 8.4 HIGH
Buffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to higher privileges via a crafted command line. NOTE: It is unclear whether there are any common situations in which redis-cli is used with, for example, a -h (aka hostname) argument from an untrusted source.
CVE-2018-0640 1 Nec 2 Aterm Hc100rc, Aterm Hc100rc Firmware 2019-01-16 6.5 MEDIUM 7.2 HIGH
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.
CVE-2018-0641 1 Nec 2 Aterm Hc100rc, Aterm Hc100rc Firmware 2019-01-16 6.5 MEDIUM 7.2 HIGH
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via tools_system.cgi date parameter, time parameter, and offset parameter.
CVE-2018-0632 1 Nec 2 Aterm W300p, Aterm W300p Firmware 2019-01-16 6.5 MEDIUM 7.2 HIGH
Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via HTTP request and response.
CVE-2018-0633 1 Nec 2 Aterm W300p, Aterm W300p Firmware 2019-01-16 6.5 MEDIUM 7.2 HIGH
Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via submit-url parameter.
CVE-2018-19150 1 Pdfforge 1 Pdf Architect 2019-01-16 6.8 MEDIUM 7.8 HIGH
Memory corruption in PDMODELProvidePDModelHFT in pdmodel.dll in pdfforge PDF Architect 6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact because of a "Data from Faulting Address controls Code Flow" issue.
CVE-2018-4257 1 Apple 1 Mac Os X 2019-01-16 10.0 HIGH 9.8 CRITICAL
In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved size validation.
CVE-2018-4258 1 Apple 1 Mac Os X 2019-01-16 10.0 HIGH 9.8 CRITICAL
In macOS High Sierra before 10.13.5, a buffer overflow was addressed with improved bounds checking.
CVE-2018-17470 3 Debian, Google, Redhat 5 Debian Linux, Chrome, Enterprise Linux Desktop and 2 more 2019-01-15 4.3 MEDIUM 7.4 HIGH
A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVE-2018-19240 1 Trendnet 4 Tv-ip110wn, Tv-ip110wn Firmware, Tv-ip121wn and 1 more 2019-01-14 7.5 HIGH 9.8 CRITICAL
Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (without authentication).
CVE-2018-19241 1 Trendnet 4 Tv-ip110wn, Tv-ip110wn Firmware, Tv-ip121wn and 1 more 2019-01-14 5.0 MEDIUM 7.5 HIGH
Buffer overflow in video.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (without authentication).
CVE-2018-19242 1 Trendnet 4 Tew-632brp, Tew-632brp Firmware, Tew-673gru and 1 more 2019-01-14 6.5 MEDIUM 8.8 HIGH
Buffer overflow in apply.cgi on TRENDnet TEW-632BRP 1.010B32 and TEW-673GRU devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (with authentication).
CVE-2018-18759 1 Modbustools 1 Modbus Slave 2019-01-14 5.0 MEDIUM 7.5 HIGH
Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow.
CVE-2018-7796 1 Schneider-electric 1 Powersuite 2 2019-01-11 6.8 MEDIUM 6.3 MEDIUM
A Buffer Error vulnerability exists in PowerSuite 2, all released versions (VW3A8104 & Patches), which could cause an overflow in the memcpy function, leading to corruption of data and program instability.
CVE-2018-20542 1 Libxsmm Project 1 Libxsmm 2019-01-11 6.8 MEDIUM 8.8 HIGH
There is a heap-based buffer-overflow at generator_spgemm_csc_reader.c (function libxsmm_sparse_csc_reader) in LIBXSMM 1.10, a different vulnerability than CVE-2018-20541 (which is in a different part of the source code and is seen at a different address).