CWE-119
High likelihoodImproper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
13,982 vulnerabilities with CWE-119
CVE-2020-3293
HIGH
Cisco RV016, RV042, RV042G, RV082, RV320, and RV325 Firmware - Authenticated Stack Overflow via Web Management Interface
CVSS 7.2
CVE-2020-3292
HIGH
Cisco Small Business RV320-0 - Authenticated RCE
CVSS 7.2
CVE-2020-3291
HIGH
Cisco RV016, RV042, RV042G, RV082, RV320, and RV325 Firmware - Authenticated Stack Overflow via Web Management Interface
CVSS 7.2
CVE-2020-3290
HIGH
Cisco Small Business RV320-0 - Authenticated RCE
CVSS 7.2
CVE-2020-3289
HIGH
Cisco RV016, RV042, RV042G, RV082, RV320, and RV325 Firmware - Authenticated Stack Overflow via Web Management Interface
CVSS 7.2
CVE-2020-3288
HIGH
Cisco Small Business RV320-0 - Authenticated RCE
CVSS 7.2
CVE-2020-3287
HIGH
Cisco RV016, RV042, RV042G, RV082, RV320, and RV325 Firmware - Authenticated Stack Overflow via Web Management Interface
CVSS 7.2
CVE-2020-3286
HIGH
Cisco RV016, RV042, RV042G, RV082, RV320, and RV325 Firmware - Authenticated Stack Overflow via Web Management Interface
CVSS 7.2
CVE-2020-3269
HIGH
Cisco RV110W-215W - Command Injection
CVSS 7.2
CVE-2020-3268
HIGH
Cisco RV110W-215W - Command Injection
CVSS 7.2
CVE-2020-11898
CRITICAL
Treck TCP/IP < 6.0.1.66 - Information Disclosure via IPv4/ICMPv4 Length Parameter Inconsistency
CVSS 9.1
CVE-2020-11896
CRITICAL
Treck TCP/IP < 6.0.1.66 - Remote Code Execution via IPv4 Tunneling
CVSS 10.0
CVE-2020-7456
MEDIUM
FreeBSD Use-After-Free via USB HID Device
CVSS 6.8
CVE-2020-10757
HIGH
Linux Kernel >4.5-rc1 - Privilege Escalation
CVSS 7.8
CVE-2020-10061
HIGH
Zephyr < 1.14.0 - Memory Corruption in Bluetooth Full-Buffer Handling
CVSS 8.1
CVE-2020-13832
CRITICAL
Android - Arbitrary Code Execution via Widevine Trustlet Memory Disclosure
CVSS 9.8
CVE-2020-13831
CRITICAL
Samsung Android O(8.x) and P(9.0) - Arbitrary Memory Mapping in Trustonic Kinibi
CVSS 9.8
CVE-2020-3258
CRITICAL
Cisco IOS - Remote Code Execution or Denial of Service
CVSS 9.8
CVE-2020-3257
HIGH
Cisco IOS - Denial of Service and Remote Code Execution
CVSS 8.1
CVE-2020-3198
CRITICAL
Cisco IOS - Remote Code Execution or Denial of Service
CVSS 9.8
CVE-2020-13754
MEDIUM
QEMU 4.2.0 - Out-of-Bounds Memory Access via MSI-X MMIO Operation
CVSS 6.7
CVE-2020-3344
MEDIUM
Cisco AMP for Endpoints Linux/Mac Connector <1.12.3.698/738 Authenticated Buffer Overflow
CVSS 5.5
CVE-2020-3343
MEDIUM
Cisco AMP for Endpoints Linux and Mac Connector < 1.12.3.698/1.12.3.738 - Authenticated Buffer Overflow
CVSS 5.5
CVE-2020-12038
MEDIUM
Rockwell Automation EDS Subsystem <= 28.0.1 - Denial of Service via EDS File Parsing
CVSS 5.5
CVE-2020-11058
LOW
FreeRDP 1.1.0-2.0.0 - Out-of-Bounds Read via Font Capability Set
CVSS 2.2
Details
Vulnerabilities
13,982
Exploit Likelihood
High