Export limit exceeded: 372218 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372218 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-22680 | 1 Nxp | 1 Mqx | 2025-04-16 | 7.3 High |
| NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution. | ||||
| CVE-2021-27439 | 1 Tencent | 1 Tencentos-tiny | 2025-04-16 | 7.3 High |
| TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of effective memory allocation size. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution. | ||||
| CVE-2021-27433 | 1 Arm | 1 Mbed Ualloc | 2025-04-16 | 7.3 High |
| ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution. | ||||
| CVE-2021-38439 | 1 Gurum | 1 Gurumdds | 2025-04-16 | 8.6 High |
| All versions of GurumDDS are vulnerable to heap-based buffer overflow, which may cause a denial-of-service condition or remotely execute arbitrary code. | ||||
| CVE-2021-38441 | 1 Eclipse | 1 Cyclonedds | 2025-04-16 | 6.6 Medium |
| Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser. | ||||
| CVE-2021-38443 | 1 Eclipse | 1 Cyclonedds | 2025-04-16 | 6.6 Medium |
| Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser. | ||||
| CVE-2021-38445 | 1 Objectcomputing | 1 Opendds | 2025-04-16 | 7 High |
| OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associated data, which may allow an attacker to remotely execute arbitrary code. | ||||
| CVE-2021-38447 | 1 Objectcomputing | 1 Opendds | 2025-04-16 | 8.6 High |
| OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic, which may result in a denial-of-service condition. | ||||
| CVE-2021-43547 | 1 Twinoakscomputing | 1 Coredx Dds | 2025-04-16 | 7.5 High |
| TwinOaks Computing CoreDX DDS versions prior to 5.9.1 are susceptible to exploitation when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure. | ||||
| CVE-2021-38423 | 1 Gurum | 1 Gurumdds | 2025-04-16 | 6.6 Medium |
| All versions of GurumDDS improperly calculate the size to be used when allocating the buffer, which may result in a buffer overflow. | ||||
| CVE-2021-38425 | 1 Eprosima | 1 Fast Dds | 2025-04-16 | 7.5 High |
| eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially crafted packet to flood a target device with unwanted traffic, which may result in a denial-of-service condition and information exposure. | ||||
| CVE-2021-38427 | 1 Rti | 2 Connext Professional, Connext Secure | 2025-04-16 | 6.6 Medium |
| RTI Connext DDS Professional and Connext DDS Secure Versions 4.2.x to 6.1.0 are vulnerable to a stack-based buffer overflow, which may allow a local attacker to execute arbitrary code. | ||||
| CVE-2021-38429 | 1 Objectcomputing | 1 Opendds | 2025-04-16 | 6.6 Medium |
| OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic, which may result in a denial-of-service condition and information exposure. | ||||
| CVE-2021-38433 | 1 Rti | 2 Connext Professional, Connext Secure | 2025-04-16 | 6.6 Medium |
| RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 vulnerable to a stack-based buffer overflow, which may allow a local attacker to execute arbitrary code. | ||||
| CVE-2021-38435 | 1 Rti | 2 Connext Professional, Connext Secure | 2025-04-16 | 6.6 Medium |
| RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 not correctly calculate the size when allocating the buffer, which may result in a buffer overflow. | ||||
| CVE-2021-27478 | 1 Opener Project | 1 Opener | 2025-04-16 | 8.2 High |
| A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may cause a denial-of-service condition. | ||||
| CVE-2021-27482 | 1 Opener Project | 1 Opener | 2025-04-16 | 7.5 High |
| A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may allow the attacker to read arbitrary data. | ||||
| CVE-2021-27498 | 1 Opener Project | 1 Opener | 2025-04-16 | 7.5 High |
| A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition. | ||||
| CVE-2021-27500 | 1 Opener Project | 1 Opener | 2025-04-16 | 7.5 High |
| A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition. | ||||
| CVE-2021-27505 | 1 Myscada | 1 Mypro | 2025-04-16 | 7.5 High |
| mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information. | ||||