Page 210 of 6004 results (0.132 seconds)

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 1

06 Jun 2021 — NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module. • http://nginx.org/en/CHANGES • CWE-190: Integer Overflow or Wraparound

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

03 Jun 2021 — Fabricating an integer overflow, A local attacker with a special user privilege may cause a system crash problem which can lead to an availability threat. • https://bugzilla.redhat.com/show_bug.cgi?id=1972621 • CWE-190: Integer Overflow or Wraparound

CVSS: 7.8EPSS: 1%CPEs: 9EXPL: 35

03 Jun 2021 — Issues addressed include integer overflow and privilege escalation vulnerabilities. • https://packetstorm.news/files/id/172836 • CWE-754: Improper Check for Unusual or Exceptional Conditions CWE-863: Incorrect Authorization •

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 0

02 Jun 2021 — An integer overflow bug in Redis version 6.0 or newer, could be exploited using the STRALGO LCS command to corrupt the heap and potentially result with remote code execution. • https://github.com/redis/redis/releases/tag/6.0.14 • CWE-190: Integer Overflow or Wraparound CWE-680: Integer Overflow to Buffer Overflow •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

02 Jun 2021 — Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02. • https://bugzilla.redhat.com/show_bug.cgi?id=498682 • CWE-190: Integer Overflow or Wraparound

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

02 Jun 2021 — Issues addressed include buffer overflow, code execution, cross site scripting, information leakage, integer overflow, traversal, and use-after-free vulnerabilities. • https://github.com/LibRaw/LibRaw/commit/4feaed4dea636cee4fee010f615881ccf76a096d • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-787: Out-of-bounds Write •

CVSS: 7.1EPSS: 0%CPEs: 6EXPL: 0

02 Jun 2021 — lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around. lrzsz versiones anteriores a 0.12.21~rc, puede filtrar información al lado receptor debido a una comprobación de longitud incorrecta en la función zsdata que causa que size_t se envuelva • http://www.ohse.de/uwe/software/lrzsz.html • CWE-190: Integer Overflow or Wraparound

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 1

01 Jun 2021 — It was discovered that FFmpeg incorrectly handled certain input files, leading to an integer overflow. • https://trac.ffmpeg.org/ticket/8285 • CWE-401: Missing Release of Memory after Effective Lifetime •

CVSS: 6.8EPSS: 2%CPEs: 22EXPL: 5

01 Jun 2021 — A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device. ... La vulnerabilidad puede ser explorada mediante el envío de un entero inesperado (superiores a 32 bits) en el parámetro page que bl... • https://packetstorm.news/files/id/162934 • CWE-190: Integer Overflow or Wraparound

CVSS: 7.2EPSS: 0%CPEs: 3EXPL: 0

01 Jun 2021 — Issues addressed include denial of service and integer overflow vulnerabilities. • https://bugzilla.redhat.com/show_bug.cgi?id=1953022 • CWE-416: Use After Free CWE-476: NULL Pointer Dereference •