Skip to main content

CWE archive

CWE-193 CVEs

Programmatic archive

215 CVEs tagged with CWE-19333 Critical, 77 High, 91 Medium, 14 Low, 0 Unrated.

CVE-2022-39274

Published Oct 6, 2022

LoRaMac-node is a reference implementation and documentation of a LoRa network node. Versions of LoRaMac-node prior to 4.7.0 are vulnerable to a buffer overflow. Improper size val…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3999

Published Aug 24, 2022

A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2020-27793

Published Aug 19, 2022

An off-by-one overflow flaw was found in radare2 due to mismatched array length in core_java.c. This could allow an attacker to cause a crash, and perform a denail of service atta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34970

Published Aug 4, 2022

Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-23400

Published May 3, 2022

A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft ImageGear 19.10. A specially-crafted PSD file can overflow a sta…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21938

Published Apr 14, 2022

A heap-based buffer overflow vulnerability exists in the Palette box parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An atta…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-3930

Published Feb 18, 2022

An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MOD…

CVSS 6.5 · Medium

CVE-2021-29529

Published May 14, 2021

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a heap buffer overflow in `tf.raw_ops.QuantizedResizeBilinear` by manipulating input…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-31875

Published Apr 29, 2021

In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-29040

Published Nov 24, 2020

An issue was discovered in Xen through 4.14.x allowing x86 HVM guest OS users to cause a denial of service (stack corruption), cause a data leak, or possibly gain privileges becau…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10062

Published Jun 5, 2020

An off-by-one error in the Zephyr project MQTT packet length decoder can result in memory corruption and possible remote code execution. NCC-ZEP-031 This issue affects: zephyrproj…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 126-150 of 215 CVEsPage 6 of 9