Skip to main content

CWE archive

CWE-122 CVEs

Programmatic archive

2,565 CVEs tagged with CWE-122235 Critical, 1,767 High, 423 Medium, 140 Low, 0 Unrated.

CVE-2017-12704

Published Aug 30, 2017

A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7555

Published Aug 17, 2017

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-9050

Published May 18, 2017

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6037

Published Apr 27, 2017

A Heap-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulnerability causes a buffer overflow when a maliciously crafted…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5225

Published Jan 12, 2017

LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1834

Published May 20, 2016

Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1,…

CVSS 7.8 · High

CVE-2014-9495

Published Jan 10, 2015

Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might allow context-dependent attackers…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7354

Published May 6, 2014

Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) png_set_sPLT or (2) png_set_text_…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7353

Published May 6, 2014

Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-dependent attackers to cause a denial of service (segmentat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0789

Published Apr 4, 2014

Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and…

CVSS 5.0 · Medium

CVE-2014-0781

Published Mar 14, 2014

Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3245

Published Jul 10, 2013

plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3459

Published Oct 13, 2009

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF f…

CVSS 8.8 · High
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort
Showing 2,551-2,565 of 2,565 CVEsPage 103 of 103