Total
14141 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-32133 | 1 Santesoft | 2 Dicom Editor, Dicom Viewer Pro | 2026-06-17 | N/A | 8.8 HIGH |
| Sante DICOM Viewer Pro J2K File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of J2K images. Crafted data in a J2K image can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15628. | |||||
| CVE-2023-32132 | 1 Santesoft | 2 Dicom Editor, Dicom Viewer Pro | 2026-06-17 | N/A | 8.8 HIGH |
| Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DCM images. Crafted data in a DCM image can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15627. | |||||
| CVE-2023-32131 | 1 Santesoft | 2 Dicom Editor, Dicom Viewer Pro | 2026-06-17 | N/A | 8.8 HIGH |
| Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DCM images. Crafted data in a DCM image can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15626. | |||||
| CVE-2023-32111 | 1 Sap | 1 Powerdesigner Proxy | 2026-06-17 | N/A | 7.5 HIGH |
| In SAP PowerDesigner (Proxy) - version 16.7, an attacker can send a crafted request from a remote host to the proxy machine and crash the proxy server, due to faulty implementation of memory management causing a memory corruption. This leads to a high impact on availability of the application. | |||||
| CVE-2023-31998 | 1 Ui | 4 Aircube, Aircube Firmware, Edgemax Edgerouter and 1 more | 2026-06-17 | N/A | 7.5 HIGH |
| A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices. | |||||
| CVE-2023-31982 | 1 Irontec | 1 Sngrep | 2026-06-17 | N/A | 7.8 HIGH |
| Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_packet_reasm_ip at /src/capture.c. | |||||
| CVE-2023-31981 | 1 Irontec | 1 Sngrep | 2026-06-17 | N/A | 7.8 HIGH |
| Sngrep v1.6.0 was discovered to contain a stack buffer overflow via the function packet_set_payload at /src/packet.c. | |||||
| CVE-2023-31976 | 1 Libming | 1 Libming | 2026-06-17 | N/A | 8.8 HIGH |
| libming v0.4.8 was discovered to contain a stack buffer overflow via the function makeswf_preprocess at /util/makeswf_utils.c. | |||||
| CVE-2023-31922 | 1 Quickjs Project | 1 Quickjs | 2026-06-17 | N/A | 7.5 HIGH |
| QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component js_proxy_isArray at quickjs.c. | |||||
| CVE-2023-31910 | 1 Jerryscript | 1 Jerryscript | 2026-06-17 | N/A | 7.8 HIGH |
| Jerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component parser_parse_function_statement at /jerry-core/parser/js/js-parser-statm.c. | |||||
| CVE-2023-31908 | 1 Jerryscript | 1 Jerryscript | 2026-06-17 | N/A | 7.8 HIGH |
| Jerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component ecma_builtin_typedarray_prototype_sort. | |||||
| CVE-2023-31907 | 1 Jerryscript | 1 Jerryscript | 2026-06-17 | N/A | 7.8 HIGH |
| Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via the component scanner_literal_is_created at /jerry-core/parser/js/js-scanner-util.c. | |||||
| CVE-2023-31906 | 1 Jerryscript | 1 Jerryscript | 2026-06-17 | N/A | 7.8 HIGH |
| Jerryscript 3.0.0(commit 1a2c047) was discovered to contain a heap-buffer-overflow via the component lexer_compare_identifier_to_chars at /jerry-core/parser/js/js-lexer.c. | |||||
| CVE-2023-31722 | 1 Nasm | 1 Netwide Assembler | 2026-06-17 | N/A | 7.8 HIGH |
| There exists a heap buffer overflow in nasm 2.16.02rc1 (GitHub commit: b952891). | |||||
| CVE-2023-31710 | 1 Tp-link | 2 Archer Ax21, Archer Ax21 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build 20230219 are vulnerable to Buffer Overflow. | |||||
| CVE-2023-31568 | 1 Podofo Project | 1 Podofo | 2026-06-17 | N/A | 8.8 HIGH |
| Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptRC4::PdfEncryptRC4. | |||||
| CVE-2023-31567 | 1 Podofo Project | 1 Podofo | 2026-06-17 | N/A | 8.8 HIGH |
| Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3. | |||||
| CVE-2023-31556 | 1 Podofo Project | 1 Podofo | 2026-06-17 | N/A | 6.5 MEDIUM |
| podofoinfo 0.10.0 was discovered to contain a segmentation violation via the function PoDoFo::PdfDictionary::findKeyParent. | |||||
| CVE-2023-31488 | 1 Cisco | 3 Ironport Email Security Appliance, Secure Email Gateway, Secure Email Gateway Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document. | |||||
| CVE-2023-31470 | 1 Pymumu | 1 Smartdns | 2026-06-17 | N/A | 9.8 CRITICAL |
| SmartDNS through 41 before 56d0332 allows an out-of-bounds write because of a stack-based buffer overflow in the _dns_encode_domain function in the dns.c file, via a crafted DNS request. | |||||
