• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-119

CVE-2018-10748

February 26, 2023 by

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a ‘show’ parameter to the ‘/userfs/bin/tcapi’ binary (in the Diagnostics component) using the ‘show ‘ function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.

CVE-2018-10749

February 26, 2023 by

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a ‘commit’ parameter to the ‘/userfs/bin/tcapi’ binary (in the Diagnostics component) using the ‘commit ‘ function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.

CVE-2018-10750

February 26, 2023 by

An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a ‘staticGet’ parameter to the ‘/userfs/bin/tcapi’ binary (in the Diagnostics component) using the ‘staticGet ‘ function and cause memory corruption. Furthermore, it is possible to redirect the flow of the program and execute arbitrary code.

CVE-2018-10689

February 26, 2023 by

blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c because the device and devno arrays are too small, as demonstrated by an invalid free when using the btt program with a crafted file.

CVE-2018-10693

February 26, 2023 by

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the device. The POST parameter “srvName” is susceptible to a buffer overflow. By crafting a packet that contains a string of 516 characters, it is possible for an attacker to execute the attack.

CVE-2018-10695

February 26, 2023 by

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send emails to his/her account when there are changes to the device’s network. However, the same functionality allows an attacker to execute commands on the device. The POST parameters “to1,to2,to3,to4” are all susceptible to buffer overflow. By crafting a packet that contains a string of 678 characters, it is possible for an attacker to execute the attack.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 298
  • Go to page 299
  • Go to page 300
  • Go to page 301
  • Go to page 302
  • Interim pages omitted …
  • Go to page 452
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE