Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

18187 risultati

VulnerabilitàAlta
CVE-2018-25224 (CVSS 8.4)

PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via return-oriented programming gadgets.

NVD (NIST)28 mar 2026
VulnerabilitàCritica
CVE-2018-25223 (CVSS 9.8)

Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service.

NVD (NIST)28 mar 2026
VulnerabilitàAlta
CVE-2018-25224 - PMS 0.42 Stack-Based Buffer Overflow via Configuration File

CVE ID :CVE-2018-25224 Published : March 28, 2026, 12:16 p.m. | 11 hours, 37 minutes ago Description :PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via return-oriented programming gadgets. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2018-25223 - Crashmail 1.6 Stack-based Buffer Overflow Remote Code Execution

CVE ID :CVE-2018-25223 Published : March 28, 2026, 12:16 p.m. | 11 hours, 37 minutes ago Description :Crashmail 1.6 contains a stack-based buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending malicious input to the application. Attackers can craft payloads with ROP chains to achieve code execution in the application context, with failed attempts potentially causing denial of service. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2018-25225 - SIPP 3.3 Stack-Based Buffer Overflow via Configuration File

CVE ID :CVE-2018-25225 Published : March 28, 2026, 12:16 p.m. | 11 hours, 37 minutes ago Description :SIPP 3.3 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious input in the configuration file. Attackers can craft a configuration file with oversized values that overflow a stack buffer, overwriting the return address and executing arbitrary code through return-oriented programming gadgets. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2018-25222 (CVSS 8.4)

SC v7.16 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 1052 bytes to overwrite the instruction pointer and execute shellcode in the application context.

NVD (NIST)28 mar 2026
VulnerabilitàCritica
CVE-2018-25221 (CVSS 9.8)

EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code execution in the application context.

NVD (NIST)28 mar 2026
VulnerabilitàCritica
CVE-2018-25220 (CVSS 9.8)

Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input string to the application. Attackers can craft a malicious payload with 1200 bytes of padding followed by a return-oriented programming chain to overwrite the instruction pointer and execute shell commands with application privileges.

NVD (NIST)28 mar 2026
VulnerabilitàCritica
CVE-2017-20229 (CVSS 9.8)

MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can craft malicious input that overflows the stack buffer and execute a return-oriented programming chain to spawn a shell with application privileges.

NVD (NIST)28 mar 2026
VulnerabilitàAlta
CVE-2017-20228 (CVSS 8.4)

Flat Assembler 1.71.21 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input to the application. Attackers can craft malicious assembly input exceeding 5895 bytes to overwrite the instruction pointer and execute return-oriented programming chains for shell command execution.

NVD (NIST)28 mar 2026
VulnerabilitàAlta
CVE-2017-20229 - MAWK 1.3.3-17 Stack-Based Buffer Overflow

CVE ID :CVE-2017-20229 Published : March 28, 2026, 12:16 p.m. | 9 hours, 37 minutes ago Description :MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can craft malicious input that overflows the stack buffer and execute a return-oriented programming chain to spawn a shell with application privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026
VulnerabilitàAlta
CVE-2018-25222 - SC v7.16 Stack-Based Buffer Overflow Remote Code Execution

CVE ID :CVE-2018-25222 Published : March 28, 2026, 12:16 p.m. | 9 hours, 37 minutes ago Description :SC v7.16 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 1052 bytes to overwrite the instruction pointer and execute shellcode in the application context. Severity: 8.6 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 mar 2026

Pagina 828 di 1516

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.