40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2013-2094
🔥 KEV Software Genérico General
8.4
HIGH
EPSS
65.9%
2013 9 PoCs

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

CVE-2020-37124
B64dec General
8.4
HIGH
EPSS
0.1%
2020 CWE-121 1 PoC

B64dec 1.1.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) with crafted input. Attackers can leverage an egg hunter technique and carefully constructed payload to inject and execute malicious code during base64 decoding process.

CVE-2023-42535
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2020-37050
Quick Player General
8.4
HIGH
EPSS
0.1%
2020 CWE-120 2 PoCs

Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious .m3l file with carefully constructed payload. Attackers can trigger the vulnerability by loading a specially crafted file through the application's file loading mechanism, potentially enabling remote code execution.

CVE-2023-52168
Software Genérico General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.

CVE-2020-37029
FTPDummy General
8.4
HIGH
EPSS
0.0%
2020 CWE-120 1 PoC

FTPDummy 4.80 contains a local buffer overflow vulnerability in its preference file handling that allows attackers to execute arbitrary code. Attackers can craft a malicious preference file with carefully constructed shellcode to trigger a structured exception handler overwrite and execute system commands.

CVE-2020-37162
Wedding Slideshow Studio General
8.4
HIGH
EPSS
0.0%
2020 CWE-122 1 PoC

Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration key input that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload of 1608 bytes to trigger a stack-based buffer overflow and execute commands through the registration key field.

CVE-2022-42271
NVIDIA DGX Servers General
8.4
HIGH
EPSS
0.2%
2022 CWE-120 1 PoC

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution

CVE-2025-34180
Manager General
8.4
HIGH
EPSS
0.0%
2025 CWE-257 1 PoC

NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access to a deployed client configuration file can decode the stored value to recover the plaintext Gateway Key. Possession of the Gateway Key allows unauthorized access to NetSupport Manager connectivity services and enables remote control of systems managed through the same key.

CVE-2022-1754
polonel/trudesk General
8.4
HIGH
EPSS
0.5%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2.

CVE-2019-25332
FTP Commander Pro General
8.4
HIGH
EPSS
0.1%
2019 CWE-121 2 PoCs

FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting the EIP register through a custom command input. Attackers can craft a malicious payload of 4108 bytes to overwrite memory and execute shellcode, demonstrating remote code execution potential.

CVE-2020-37040
Code::Blocks General
8.4
HIGH
EPSS
0.0%
2020 CWE-120 1 PoC

Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious file name with Unicode characters. Attackers can trigger the vulnerability by pasting a specially crafted payload into the file name field during project creation, potentially executing system commands like calc.exe.

CVE-2024-3435
parisneo/lollms-webui General
8.4
HIGH
EPSS
0.4%
2024 CWE-29 1 PoC

A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an attacker to manipulate the application's configuration by sending specially crafted JSON payloads. This could lead to remote code execution (RCE) by bypassing existing patches designed to mitigate such vulnerabilities.

CVE-2022-22077
Snapdragon Mobile General
8.4
HIGH
EPSS
0.1%
2022 1 PoC

Memory corruption in graphics due to use-after-free in graphics dispatcher logic in Snapdragon Mobile

CVE-2021-1984
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables General
8.4
HIGH
EPSS
0.1%
2021 1 PoC

Possible buffer overflow due to improper validation of index value while processing the plugin block in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

CVE-2021-45543
Software Genérico General
8.4
HIGH
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R8000 before 1.0.4.74, RAX200 before 1.0.4.120, R8000P before 1.4.2.84, R7900P before 1.4.2.84, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12, and RBK852 before 3.2.17.12.

CVE-2019-25331
AVS Audio Converter General
8.4
HIGH
EPSS
0.0%
2019 CWE-121 1 PoC

AVS Audio Converter 9.1 contains a local buffer overflow vulnerability that allows local attackers to overwrite CPU registers by manipulating the 'Exit folder' input field. Attackers can craft a specially designed text file with 264 bytes of padding followed by register overwrite values to compromise the application and potentially execute arbitrary code.

CVE-2024-2608
Firefox General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVE-2021-45574
Software Genérico General
8.4
HIGH
EPSS
0.1%
2021 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6, RBR750 before 3.2.16.6, RBS750 before 3.2.16.6, RBK852 before 3.2.16.6, RBR850 before 3.2.16.6, and RBS850 before 3.2.16.6.

CVE-2023-30680
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2023 1 PoC

Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.