Security
Headlines
HeadlinesLatestCVEs

Tag

#buffer_overflow

Critical FortiOS and FortiProxy Vulnerability Likely Exploited - Patch Now!

Fortinet on Monday disclosed that a newly patched critical flaw impacting FortiOS and FortiProxy may have been "exploited in a limited number of cases" in attacks targeting government, manufacturing, and critical infrastructure sectors. The vulnerability, tracked as CVE-2023-27997 (CVSS score: 9.2), concerns a heap-based buffer overflow vulnerability in FortiOS and FortiProxy SSL-VPN that could

The Hacker News
#vulnerability#web#ios#microsoft#buffer_overflow#zero_day#ssl#The Hacker News
CVE-2023-34942: cve/MAC_Address_StackBOF.md at main · OlivierLaflamme/cve

** UNSUPPORTED WHEN ASSIGNED ** Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the mac parameter at /start-apply.html. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-34940: cve/URLFilterList_Stack_BOF.md at main · OlivierLaflamme/cve

** UNSUPPORTED WHEN ASSIGNED ** Asus RT-N10LX Router v2.0.0.39 was discovered to contain a stack overflow via the url parameter at /start-apply.html. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

strongSwan VPN Charon Server Buffer Overflow

Proof of concept exploit for a buffer overflow in strongSwan VPN's charon server.

librelp Remote Code Execution

Proof of concept exploit for a buffer overflow remote code execution vulnerability in librelp.

CVE-2023-34364: Develop, Deploy & Manage High-Impact Business Apps | Progress Software

A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large value for certain options of a connection string may overrun the buffer allocated to process the string value. This allows an attacker to execute code of their choice on an affected host by copying carefully selected data that will be executed as code.

RenderDoc 1.26 Local Privilege Escalation / Remote Code Execution

RenderDoc versions 1.26 and below suffer from integer underflow, integer overflow, and symlink vulnerabilities.

CVE-2023-25177

Delta Electronics' CNCSoft-B DOPSoft versions 1.0.0.4 and prior are vulnerable to stack-based buffer overflow, which could allow an attacker to execute arbitrary code.