Filtered by CWE-120
Total 3765 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-26354 1 Amd 304 Amd 3015ce, Amd 3015ce Firmware, Amd 3015e and 301 more 2025-01-28 5.5 Medium
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.
CVE-2024-0146 2025-01-28 7.8 High
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause memory corruption. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or data tampering.
CVE-2022-36330 1 Westerndigital 6 My Cloud Home, My Cloud Home Duo, My Cloud Home Duo Firmware and 3 more 2025-01-28 1.9 Low
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability. This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191. 
CVE-2023-43542 1 Qualcomm 418 9205 Lte Modem, 9205 Lte Modem Firmware, Aqt1000 and 415 more 2025-01-27 7.8 High
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
CVE-2023-43538 1 Qualcomm 274 Aqt1000, Aqt1000 Firmware, Ar8035 and 271 more 2025-01-27 9.3 Critical
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
CVE-2023-43556 1 Qualcomm 136 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 133 more 2025-01-27 9.3 Critical
Memory corruption in Hypervisor when platform information mentioned is not aligned.
CVE-2024-30259 1 Eprosima 1 Fast Dds 2025-01-27 8.2 High
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves malformed `RTPS` packet, heap buffer overflow occurs on the subscriber. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.
CVE-2023-31475 1 Gl-inet 64 Gl-a1300, Gl-a1300 Firmware, Gl-ap1300 and 61 more 2025-01-27 9 Critical
An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.
CVE-2023-22661 1 Intel 20 Server System D50tnp1mhcpac, Server System D50tnp1mhcpac Firmware, Server System D50tnp1mhcrac and 17 more 2025-01-27 8.2 High
Buffer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.
CVE-2022-43507 1 Intel 1 Quickassist Technology Engine 2025-01-27 7.5 High
Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access.
CVE-2024-24451 2025-01-24 7.5 High
A stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.
CVE-2022-47090 2025-01-24 7.8 High
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/av_parsers.c, check needed for num_exp_tile_columns
CVE-2023-6881 1 Zephyrproject 1 Zephyr 2025-01-23 7.3 High
Possible buffer overflow in is_mount_point
CVE-2024-0816 1 Zyxel 130 Ax7501-b0, Ax7501-b0 Firmware, Ax7501-b1 and 127 more 2025-01-22 5.5 Medium
The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.
CVE-2023-37929 1 Zyxel 64 Ax7501-b0, Ax7501-b0 Firmware, Ax7501-b1 and 61 more 2025-01-22 6.5 Medium
The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.
CVE-2024-8748 1 Zyxel 127 Ax7501-b0, Ax7501-b0 Firmware, Ax7501-b1 and 124 more 2025-01-21 7.5 High
A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmware versions through V5.50(ABOM.8.4)C0 could allow an attacker to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP POST request to a vulnerable device.
CVE-2024-9197 1 Zyxel 72 Ax7501-b0, Ax7501-b0 Firmware, Ax7501-b1 and 69 more 2025-01-21 4.9 Medium
A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP GET request to a vulnerable device if the function ZyEE is enabled.
CVE-2023-23300 1 Garmin 1 Connect-iq 2025-01-21 9.8 Critical
The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying data. A malicious application could call the API method with specially crafted parameters and hijack the execution of the device's firmware.
CVE-2023-23302 1 Garmin 1 Connect-iq 2025-01-21 9.8 Critical
The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object and hijack the execution of the device's firmware.
CVE-2023-23303 1 Garmin 1 Connect-iq 2025-01-21 9.8 Critical
The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object and hijack the execution of the device's firmware.