Show filters
1,621 Total Results
Displaying 281-290 of 1,621
Sort by:
Attacker Value
Unknown
CVE-2024-5950
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Deep Sea Electronics DSE855 Multipart Value Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of multipart form variables. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23172.
0
Attacker Value
Unknown
CVE-2024-5948
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Deep Sea Electronics DSE855 Multipart Boundary Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of multipart boundaries. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23170.
0
Attacker Value
Unknown
CVE-2024-37635
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg
0
Attacker Value
Unknown
CVE-2024-37633
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiGuestCfg
0
Attacker Value
Unknown
CVE-2024-37631
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the File parameter in function UploadCustomModule.
0
Attacker Value
Unknown
CVE-2024-37029
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
Fuji Electric Tellus Lite V-Simulator
is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2024-28877
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
MicroDicom DICOM Viewer is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code on affected installations of DICOM Viewer. User interaction is required to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2024-30083
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Windows Standards-Based Storage Management Service Denial of Service Vulnerability
0
Attacker Value
Unknown
CVE-2024-26010
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15, 6.2.0 through 6.2.16, 6.0.0 through 6.0.18, FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specially crafted packets.
0
Attacker Value
Unknown
CVE-2024-23110
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0 all versions allows attacker to execute unauthorized code or commands via specially crafted commands
0