Vulnerabilities (CVE)

Filtered by CWE-123
Total 48 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-3971 1 Sophos 1 Hitmanpro.alert 2026-06-17 7.2 HIGH 7.8 HIGH
An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the driver to write data under controlled by an attacker address, resulting in memory corruption. An attacker can send IRP request to trigger this vulnerability.
CVE-2018-16962 2 Apple, Webroot 2 Macos, Secureanywhere 2026-06-17 7.2 HIGH 7.8 HIGH
Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges.
CVE-2018-15376 1 Cisco 1 Ios 2026-06-17 7.2 HIGH 6.7 MEDIUM
A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected device. The vulnerability is due to the presence of certain test commands that were intended to be available only in internal development builds of the affected software. An attacker could exploit this vulnerability by using these commands on an affected device. A successful exploit could allow the attacker to write arbitrary values to arbitrary locations in the memory space of the affected device.
CVE-2018-15375 1 Cisco 1 Ios 2026-06-17 7.2 HIGH 6.7 MEDIUM
A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected device. The vulnerability is due to the presence of certain test commands that were intended to be available only in internal development builds of the affected software. An attacker could exploit this vulnerability by using these commands on an affected device. A successful exploit could allow the attacker to write arbitrary values to arbitrary locations in the memory space of the affected device.
CVE-2018-12036 1 Owasp 1 Dependency-check 2026-06-17 6.8 MEDIUM 7.8 HIGH
OWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal filenames.
CVE-2017-6282 2 Google, Nvidia 3 Android, Shield Tv, Shield Tv Firmware 2026-06-17 7.2 HIGH 7.8 HIGH
NVIDIA Tegra kernel driver contains a vulnerability in NVMAP where an attacker has the ability to write an arbitrary value to an arbitrary location which may lead to an escalation of privileges. This issue is rated as high.
CVE-2017-10994 1 Foxitsoftware 2 Foxit Reader, Phantompdf 2026-06-17 9.3 HIGH 7.3 HIGH
Foxit Reader before 8.3.1 and PhantomPDF before 8.3.1 have an Arbitrary Write vulnerability, which allows remote attackers to execute arbitrary code via a crafted document.
CVE-2015-8271 1 Rtmpdump Project 1 Rtmpdump 2026-06-17 7.5 HIGH 9.8 CRITICAL
The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.