Skip to main content

CWE archive

CWE-121 CVEs

Programmatic archive

3,522 CVEs tagged with CWE-121584 Critical, 2,296 High, 571 Medium, 70 Low, 1 Unrated.

CVE-2021-38408

Published Sep 9, 2021

A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user-supplied data may allow remo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-33019

Published Aug 30, 2021

A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by processing a specially crafted project file, which may allow…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34730

Published Aug 18, 2021

A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1

CVE-2021-32947

Published Aug 11, 2021

FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32943

Published Aug 10, 2021

The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/SCADA (WebAccess/SCADA version…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-0276

Published Jul 15, 2021

A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending spe…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-34830

Published Jul 15, 2021

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Authentication is not required to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34827

Published Jul 15, 2021

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1330 1.13B01 BETA routers. Authentication is not required to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21821

Published Jul 8, 2021

A stack-based buffer overflow vulnerability exists in the PDF process_fontname functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to code execut…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-31507

Published Jun 29, 2021

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this v…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25386

Published Jun 11, 2021

An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on m…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-25385

Published Jun 11, 2021

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on m…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 3,151-3,175 of 3,522 CVEsPage 127 of 141