Skip to main content

CWE archive

CWE-129 CVEs

Programmatic archive

601 CVEs tagged with CWE-12957 Critical, 404 High, 133 Medium, 7 Low, 0 Unrated.

CVE-2023-36307

Published Sep 5, 2023

ZPLGFA 1.1.1 allows attackers to cause a panic (because of an integer index out of range during a ConvertToGraphicField call) via an image of zero width. NOTE: it is unclear wheth…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36308

Published Sep 5, 2023

disintegration Imaging 1.6.2 allows attackers to cause a panic (because of an integer index out of range during a Grayscale call) via a crafted TIFF file to the scan function of s…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29458

Published Jul 13, 2023

Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31194

Published Jul 5, 2023

An improper array index validation vulnerability exists in the GraphPlanar::Write functionality of Diagon v1.0.139. A specially crafted markdown file can lead to memory corruption…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2008

Published Apr 14, 2023

A flaw was found in the Linux kernel's udmabuf device driver. The specific flaw exists within a fault handler. The issue results from the lack of proper validation of user-supplie…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-20080

Published Mar 23, 2023

A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial…

CVSS 8.6 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 301-325 of 601 CVEsPage 13 of 25