Vulnerabilities (CVE)

Filtered by CWE-119
Total 13319 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-27403 1 Siemens 1 Tecnomatix Plant Simulation 2024-11-21 N/A 7.8 HIGH
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains a memory corruption vulnerability while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20303, ZDI-CAN-20348)
CVE-2023-27286 1 Ibm 2 Aspera Cargo, Aspera Connect 2024-11-21 N/A 8.4 HIGH
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.
CVE-2023-27285 1 Ibm 2 Aspera Cargo, Aspera Connect 2024-11-21 N/A 8.4 HIGH
IBM Aspera Connect 4.2.5 and IBM Aspera Cargo 4.2.5 is vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248625.
CVE-2023-27284 1 Ibm 2 Aspera Cargo, Aspera Connect 2024-11-21 N/A 8.4 HIGH
IBM Aspera Cargo 4.2.5 and IBM Aspera Connect 4.2.5 are vulnerable to a buffer overflow, caused by improper bounds checking. An attacker could overflow a buffer and execute arbitrary code on the system. IBM X-Force ID: 248616.
CVE-2023-25545 1 Intel 20 Server System D50tnp1mhcpac, Server System D50tnp1mhcpac Firmware, Server System D50tnp1mhcrac and 17 more 2024-11-21 N/A 8.2 HIGH
Improper buffer restrictions in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.
CVE-2023-25527 1 Nvidia 2 Dgx H100, Dgx H100 Firmware 2024-11-21 N/A 7.8 HIGH
NVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an authenticated local attacker may cause corruption of kernel memory. A successful exploit of this vulnerability may lead to arbitrary kernel code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
CVE-2023-25509 1 Nvidia 2 Dgx-1, Sbios 2024-11-21 N/A 6.0 MEDIUM
NVIDIA DGX-1 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, and escalation of privileges.
CVE-2023-24817 1 Riot-os 1 Riot 2024-11-21 N/A 7.5 HIGH
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2023.04, an attacker can send a crafted frame to the device resulting in an integer underflow and out of bounds access in the packet buffer. Triggering the access at the right time will corrupt other packets or the allocator metadata. Corrupting a pointer will lead to denial of service. This issue is fixed in version 2023.04. As a workaround, disable SRH in the network stack.
CVE-2023-24585 2 Silabs, Weston-embedded 3 Gecko Software Development Kit, Cesium Net, Uc-http 2024-11-21 N/A 7.7 HIGH
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
CVE-2023-24564 1 Siemens 1 Solid Edge Se2023 2024-11-21 N/A 7.8 HIGH
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2). The affected application contains a memory corruption vulnerability while parsing specially crafted DWG files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19069)
CVE-2023-23567 1 Accusoft 1 Imagegear 2024-11-21 N/A 8.1 HIGH
A heap-based buffer overflow vulnerability exists in the CreateDIBfromPict functionality of Accusoft ImageGear 20.1. A specially crafted file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2023-22882 1 Zoom 1 Zoom 2024-11-21 N/A 6.5 MEDIUM
Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.
CVE-2023-22881 1 Zoom 1 Zoom 2024-11-21 N/A 6.5 MEDIUM
Zoom clients before version 5.13.5 contain a STUN parsing vulnerability. A malicious actor could send specially crafted UDP traffic to a victim Zoom client to remotely cause the client to crash, causing a denial of service.
CVE-2023-22313 1 Intel 5 Qat Driver, Qat Driver Firmware, Quickassist Technology Driver and 2 more 2024-11-21 N/A 2.3 LOW
Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to potentially enable information disclosure via local access.
CVE-2023-22297 1 Intel 20 Server System D50tnp1mhcpac, Server System D50tnp1mhcpac Firmware, Server System D50tnp1mhcrac and 17 more 2024-11-21 N/A 8.2 HIGH
Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.
CVE-2023-21663 1 Qualcomm 76 Aqt1000, Aqt1000 Firmware, Qca6420 and 73 more 2024-11-21 N/A 6.7 MEDIUM
Memory Corruption while accessing metadata in Display.
CVE-2023-21654 1 Qualcomm 112 Apq8096au, Apq8096au Firmware, Aqt1000 and 109 more 2024-11-21 N/A 6.7 MEDIUM
Memory corruption in Audio during playback session with audio effects enabled.
CVE-2023-21637 1 Qualcomm 110 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 107 more 2024-11-21 N/A 6.7 MEDIUM
Memory corruption in Linux while calling system configuration APIs.
CVE-2023-21634 1 Qualcomm 102 Aqt1000, Aqt1000 Firmware, Fastconnect 6200 and 99 more 2024-11-21 N/A 6.7 MEDIUM
Memory Corruption in Radio Interface Layer while sending an SMS or writing an SMS to SIM.
CVE-2023-21628 1 Qualcomm 566 Apq8017, Apq8017 Firmware, Apq8064au and 563 more 2024-11-21 N/A 8.4 HIGH
Memory corruption in WLAN HAL while processing WMI-UTF command or FTM TLV1 command.