Skip to main content

CWE archive

CWE-122 CVEs

Programmatic archive

2,534 CVEs tagged with CWE-122228 Critical, 1,749 High, 420 Medium, 137 Low, 0 Unrated.

CVE-2022-43171

Published Nov 17, 2022

A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted Mac…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24942

Published Nov 15, 2022

Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-20946

Published Nov 15, 2022

A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote att…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-2809

Published Oct 27, 2022

A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser code using AFL++ with address sanitizer enabled to find smal…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35712

Published Oct 14, 2022

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code executi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-35711

Published Oct 14, 2022

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code executi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-37864

Published Oct 11, 2022

A vulnerability has been identified in Solid Edge (All Versions < SE2022MP9). The affected application contains an out of bounds write past the fixed-length heap-based buffer whil…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39852

Published Oct 7, 2022

A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker to perform code execution.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38742

Published Sep 23, 2022

Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS requ…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2347

Published Sep 23, 2022

There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the t…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2566

Published Sep 23, 2022

A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,051-2,075 of 2,534 CVEsPage 83 of 102