#bufferoverflow — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bufferoverflow, aggregated by home.social.
-
CVE-2026-54212: CRITICAL buffer overflow in Tobit TeamDavid Webbox API (≤ Rollout 524). Crafted JSON lets unauthenticated attackers crash servers; RCE possible if combined with other flaws. Restrict API, monitor activity. https://radar.offseq.com/threat/cve-2026-54212-cwe-787-out-of-bounds-write-in-tobit-laboratories-ag-teamdavid-2e946f5b4b7b0ab5 #OffSeq #CVE #bufferOverflow #infosec
-
7-Zip vulnerability CVE-2026-14266 (CVSS 7.0) allows remote code execution via crafted XZ data. Update to 7-Zip 26.02. No exploitation confirmed.
#7Zip #CVE202614266 #RCE #BufferOverflow #ZDI #CyberSecurity
-
🔍 HIGH severity: Buffer overflow in GALAYOU Y4 v1.0.0 (CVE-2026-12192). Exploitable via local network — no patch or vendor response yet. Restrict network access & monitor for updates. https://radar.offseq.com/threat/cve-2026-12192-buffer-overflow-in-galayou-y4-555d7b50 #OffSeq #Vuln #IoTSecurity #BufferOverflow
-
CVE-2026-9360: HIGH severity buffer overflow in Edimax EW-7438RPn v1.28a. Remotely exploitable, public exploit released, no patch yet. Disable remote access or isolate! Details: https://radar.offseq.com/threat/cve-2026-9360-buffer-overflow-in-edimax-ew-7438rpn-4e6fd99f #OffSeq #Vuln #IoTSecurity #BufferOverflow
-
🚨 HIGH severity (CVSS 8.7): Edimax EW-7438RPn v1.0 – 1.31 stack-based buffer overflow in /goform/mp (webs arg). Remote code execution possible, public exploit out. No vendor patch. Restrict device access! CVE-2026-9348 https://radar.offseq.com/threat/cve-2026-9348-stack-based-buffer-overflow-in-edima-d83420d9 #OffSeq #IoTSecurity #BufferOverflow
-
Palo Alto Networks Exploits Critical PAN-OS Flaw in Limited Attacks
Palo Alto Networks has patched a critical flaw in its PAN-OS software, CVE-2026-0300, which allowed hackers to execute malicious code with root privileges - and the company says it's already been exploited in targeted attacks. The vulnerability, a buffer overflow in the User-ID Authentication Portal service, could be triggered by…
#Panos #Cve20260300 #PaloAltoNetworks #BufferOverflow #Exploitation
-
Palo Alto Networks Discloses Active Exploitation of PAN-OS Flaw Enabling Espionage
Palo Alto Networks has uncovered active exploitation of a high-severity flaw in PAN-OS software, allowing attackers to execute arbitrary code with root privileges and inject shellcode into vulnerable systems. This critical vulnerability, tracked as CVE-2026-0300, enables unauthenticated remote code execution,…
#Panos #Cve20260300 #RemoteCodeExecution #BufferOverflow #PaloAltoNetworks
-
Palo Alto Networks Discloses Zero-Day Flaw in PAN-OS Software
Palo Alto Networks has issued a warning about a zero-day flaw in its PAN-OS software, tracked as CVE-2026-0300, which allows unauthenticated remote code execution with root privileges. This buffer overflow vulnerability in the User-ID Authentication Portal poses a high risk to PA-Series and VM-Series firewalls.
#ZeroDay #Cve20260300 #Panos #PaloAltoNetworks #BufferOverflow
-
Palo Alto Networks Flaw Exploited for Remote Code Execution
A critical vulnerability in Palo Alto Networks' PAN-OS software has been exploited, allowing hackers to execute malicious code with root privileges on firewalls - and all it takes is a few specially crafted packets. This buffer overflow flaw, tracked as CVE-2026-0300, puts PA-Series and VM-Series firewalls at risk of remote code…
#PaloAltoNetworks #RemoteCodeExecution #Cve20260300 #BufferOverflow #Panos
-
🛑 HIGH severity: Buffer overflow in Tenda F456 (v1.0.0.5) via /goform/P2pListFilter ('menufacturer/Go'). Public exploit available, no patch. Limit exposure & monitor systems. CVE-2026-7019. https://radar.offseq.com/threat/cve-2026-7019-buffer-overflow-in-tenda-f456-8fc2e156 #OffSeq #Tenda #Vuln #BufferOverflow
-
⚠️ HIGH-severity buffer overflow (CVE-2026-6560) in H3C Magic B0 (100R002) allows remote code execution or DoS via Edit_BasicSSID in /goform/aspForm. No patch yet; restrict access & monitor updates. https://radar.offseq.com/threat/cve-2026-6560-buffer-overflow-in-h3c-magic-b0-f38a59da #OffSeq #H3C #Vuln #BufferOverflow
-
⚠️ HIGH severity: CVE-2026-4535 in Tenda FH451 (v1.0.0.9) — stack-based buffer overflow in /goform/WrlclientSet. Remote, unauthenticated code execution possible. Patch or mitigate now! https://radar.offseq.com/threat/cve-2026-4535-stack-based-buffer-overflow-in-tenda-8f2fc263 #OffSeq #vulnerability #IoT #bufferOverflow
-
⚠️ HIGH severity: CVE-2026-4535 in Tenda FH451 (v1.0.0.9) — stack-based buffer overflow in /goform/WrlclientSet. Remote, unauthenticated code execution possible. Patch or mitigate now! https://radar.offseq.com/threat/cve-2026-4535-stack-based-buffer-overflow-in-tenda-8f2fc263 #OffSeq #vulnerability #IoT #bufferOverflow
-
🚨 CVE-2026-4529: HIGH severity stack-based buffer overflow in D-Link DHP-1320 (1.00WWB04) via SOAP Handler. Public exploit out. Device is EOL, no patch — isolate or replace now! https://radar.offseq.com/threat/cve-2026-4529-stack-based-buffer-overflow-in-d-lin-7f100378 #OffSeq #Vulnerability #DLink #BufferOverflow #InfoSec
-
⚠️ CVE-2026-2086: HIGH-severity buffer overflow in UTT HiPER 810G (≤1.7.7-171114). Remote code execution possible, public exploit exists, no patch. Segment networks, disable remote mgmt, monitor for attacks. https://radar.offseq.com/threat/cve-2026-2086-buffer-overflow-in-utt-hiper-810g-43cb38da #OffSeq #UTT #Infosec #BufferOverflow
-
Krytyczna podatność (CVSS 9.8/10.0) w popularnym pakiecie do monitorowania urządzeń – Net-SNMP
W popularnym pakiecie Net-SNMP, służącym do monitorowania i zarządzania urządzeniami sieciowymi wykryto krytyczną lukę bezpieczeństwa typu stack based buffer overflow. Podatność została znaleziona przez badacza bezpieczeństwa buddurid oraz zgłoszona w ramach programu Trend Micro Zero Day Initiative (ZDI). TLDR: Dla osób spotykających się z tym programem po raz pierwszy krótkie wyjaśnienie....
-
Krytyczna podatność (CVSS 9.8/10.0) w popularnym pakiecie do monitorowania urządzeń – Net-SNMP
W popularnym pakiecie Net-SNMP, służącym do monitorowania i zarządzania urządzeniami sieciowymi wykryto krytyczną lukę bezpieczeństwa typu stack based buffer overflow. Podatność została znaleziona przez badacza bezpieczeństwa buddurid oraz zgłoszona w ramach programu Trend Micro Zero Day Initiative (ZDI). TLDR: Dla osób spotykających się z tym programem po raz pierwszy krótkie wyjaśnienie....
-
The SQL Slammer worm was the fastest spreading malware in Internet history. It exploited a buffer overflow vulnerability in Windows systems and could be transmitted and executed with minimal latency. Today, it is considered the precursor of ransomware and spyware attacks.
#SQLslammerWorm #computerWorms, #malware #bufferOverflow #vulnerabilities #cybersecurity #cyberattacks
https://negativepid.blog/the-sql-slammer-worm/
https://negativepid.blog/the-sql-slammer-worm/ -
🚨 CVE-2025-14534: CRITICAL buffer overflow in UTT 进取 512W (≤3.1.7.7-171114). Remote, unauthenticated exploit — public code available. Isolate & restrict /goform/formNatStaticMap now! https://radar.offseq.com/threat/cve-2025-14534-buffer-overflow-in-utt-512w-46bf1244 #OffSeq #CVE #BufferOverflow #NetworkSecurity
-
The SQL Slammer worm was the fastest spreading malware in Internet history. It exploited a buffer overflow vulnerability in Windows systems and could be transmitted and executed with minimal latency. Today, it is considered the precursor of ransomware and spyware attacks.
#SQLslammerWorm #computerWorms, #malware #bufferOverflow #vulnerabilities #cybersecurity #cyberattacks
https://negativepid.blog/the-sql-slammer-worm/
https://negativepid.blog/the-sql-slammer-worm/ -
⚠️ CVE-2025-14196 (HIGH, CVSS 8.7): Remote buffer overflow in H3C Magic B1 (≤100R004). Public exploit available, no patch. Isolate devices, restrict access, monitor for /goform/aspForm attacks. https://radar.offseq.com/threat/cve-2025-14196-buffer-overflow-in-h3c-magic-b1-e84401a0 #OffSeq #H3C #BufferOverflow #Vuln
-
The SQL Slammer worm was the fastest spreading malware in Internet history. It exploited a buffer overflow vulnerability in Windows systems and could be transmitted and executed with minimal latency. Today, it is considered the precursor of ransomware and spyware attacks.
#SQLslammerWorm #computerWorms, #malware #bufferOverflow #vulnerabilities #cybersecurity #cyberattacks
https://negativepid.blog/the-sql-slammer-worm/
https://negativepid.blog/the-sql-slammer-worm/ -
The SQL Slammer worm was the fastest spreading malware in Internet history. It exploited a buffer overflow vulnerability in Windows systems and could be transmitted and executed with minimal latency. Today, it is considered the precursor of ransomware and spyware attacks.
#SQLslammerWorm #computerWorms, #malware #bufferOverflow #vulnerabilities #cybersecurity #cyberattacks
https://negativepid.blog/the-sql-slammer-worm/
https://negativepid.blog/the-sql-slammer-worm/ -
🛡️ CVE-2025-13258: HIGH severity buffer overflow in Tenda AC20 routers (≤16.03.08.12) via /goform/WifiExtraSet. Public exploit out—remotely exploitable, no auth needed. Restrict access, monitor, and patch ASAP. https://radar.offseq.com/threat/cve-2025-13258-buffer-overflow-in-tenda-ac20-f036b48b #OffSeq #CVE2025 #Tenda #BufferOverflow
-
The SQL Slammer worm was the fastest spreading malware in Internet history. It exploited a buffer overflow vulnerability in Windows systems and could be transmitted and executed with minimal latency. Today, it is considered the precursor of ransomware and spyware attacks.
#SQLslammerWorm #computerWorms, #malware #bufferOverflow #vulnerabilities #cybersecurity #cyberattacks
https://negativepid.blog/the-sql-slammer-worm/
https://negativepid.blog/the-sql-slammer-worm/ -
ein ganz gemeiner #BufferOverflow um #remoters content reinzuhacken ;)
-
ein ganz gemeiner #BufferOverflow um #remoters content reinzuhacken ;)
-
"There are no workarounds that address this vulnerability.", not a quote you want to read about your fleet of Cisco devices running IOS and IOS XE Software! You must patch!
Cisco devices have been under attack due to zero-day critical RCE flaws as detailed in CVE-2025-20333, CVE-2025-20363, and CVE-2025-20362, resulting in a denial of service (DoS) condition.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-cli-EB7cZ6yO #Cisco #CitrixIOS #Networks #CyberAttack #CyberSecurity #DDOS #bufferoverflow #CISA
-
"There are no workarounds that address this vulnerability.", not a quote you want to read about your fleet of Cisco devices running IOS and IOS XE Software! You must patch!
Cisco devices have been under attack due to zero-day critical RCE flaws as detailed in CVE-2025-20333, CVE-2025-20363, and CVE-2025-20362, resulting in a denial of service (DoS) condition.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-cli-EB7cZ6yO #Cisco #CitrixIOS #Networks #CyberAttack #CyberSecurity #DDOS #bufferoverflow #CISA
-
Chińskie kamery z krytycznymi podatnościami – Dahua Hero C1 i inne
Rumuńska firma Bitdefender opublikowała broszurę, w której informuje o załatanych niedawno podatnościach odnalezionych w kamerach chińskiego producenta Dahua. Badacze zaznaczają, że podczas wewnętrznego audytu firmy wytwarzającej te kamery ujawniono dłuższą listę podatnych urządzeń. Użytkownicy modeli: oraz (wszystkie firmware wydane przed 16.04.2025) powinni jak najszybciej dokonać aktualizacji urządzeń. Wykryte podatności to...
#WBiegu #BufferOverflow #Cve #Dahua #Kamery #Podatność
https://sekurak.pl/chinskie-kamery-z-krytycznymi-podatnosciami-dahua-hero-c1-i-inne/
-
Chińskie kamery z krytycznymi podatnościami – Dahua Hero C1 i inne
Rumuńska firma Bitdefender opublikowała broszurę, w której informuje o załatanych niedawno podatnościach odnalezionych w kamerach chińskiego producenta Dahua. Badacze zaznaczają, że podczas wewnętrznego audytu firmy wytwarzającej te kamery ujawniono dłuższą listę podatnych urządzeń. Użytkownicy modeli: oraz (wszystkie firmware wydane przed 16.04.2025) powinni jak najszybciej dokonać aktualizacji urządzeń. Wykryte podatności to...
#WBiegu #BufferOverflow #Cve #Dahua #Kamery #Podatność
https://sekurak.pl/chinskie-kamery-z-krytycznymi-podatnosciami-dahua-hero-c1-i-inne/
-
@byorgey for some reason I feel like I have to add, the reason Python is better than C is that you don't have to know the definition of the word "pointer". There really isn't any other reason. Don't touch that! It uses pointers!
(ok, I don't mind not using curly braces)
(p.s. check out the etymology of "cat" in Linux) -
I published my WriteUp of MagicGardens box from @hackthebox_eu
👇👇👇
https://v0lk3n.github.io/writeup/HackTheBox/Box/MagicGardens/HTB-MagicGardens_WriteUp
I hope that you will like it :)
#HTB #BufferOverflow #CSRF #XSS #DevTools #Missconfiguration #docker #django #Pentest #CyberSecurity #HackTheBox
-
Open-Source ClamAV Releases Security Update for Buffer Overflow Vulnerability – Patch Now https://gbhackers.com/clamav-buffer-overflow-vulnerability-patch-now/ #CVE/vulnerability #CyberSecurityNews #Bufferoverflow #Vulnerability #cybersecurity
-
#Ubuntu #Linux #mtr report mode is still #broken causes #bufferoverflow
Start: 2024-10-07T09:46:22+0000
*** buffer overflow detected ***: terminated -
Można bez uwierzytelnienia przejmować pewne routery / urządzenia WiFi. Zobacz podatność CVE-2024-20017
Pokazał się detaliczny opis podatności oraz exploit. Luka występuje w chipsecie MediaTek MT6890, MT7915, MT7916, MT7981, MT7986 (a dokładniej w oprogramowaniu, które jest do niego dołączane przez producenta , a jeszcze dokładniej w linuksowym wappd). Przykładowy exploit został pokazany dla Netgear WAX206. Producent w opisie łatki podaje taką informację: In...
-
Hello everyone.
In today's article, we examine buffer overflow in detail.
I wish everyone a good read.
https://denizhalil.com/2024/09/03/buffer-overflow-security/
#cyber #cybersecurity #bufferoverflow #cyberattack #ethicalhacking #programming
-
My understanding of the #CrowdStrike root cause:
They pushed out a defective "Channel file" (some kind of config?) to #FalconSensor customers. This gets uploaded to CrowdStrike's Windows kernel module, which fails to perform correct bounds checking. The resulting #BufferOverflow results in a crash of the kernel module and thus the entire system. Correct?
#BSOD -
So, there is bug in all of the ARM CPUs now
-
7-Zip quietly fixes a buffer overflow vulnerability
https://stackdiary.com/7-zip-quietly-fixes-a-buffer-overflow-vulnerability/
#CyberSecurity #InfoSec #DataBreach #Vulnerability #SoftwareUpdate #7Zip #TechNews #SecurityPatch #BufferOverflow #DataProtection #SecurityAlert #HackerNews #Malware #SecureSoftware #Privacy #CyberAttack #TechAlert #BugFix #SecurityBreach #DataSecurity #CyberSafety #InfosecNews #TechUpdates #SecurityFirst #Exploit #SecureTech #OnlineSecurity #SecureUpdate #SecurityMatters #TechSafety
-
Just realised that the code I wrote which contains a #BufferOverflow if you compile it for a 256 bit CPU is also not #ThreadSafe. Truly I am an awful person.
-
Buffer Overflow in GNU C Library Affects Older Versions
Date: April 17, 2024
CVE: CVE-2024-2961
Vulnerability Type: Out-of-bounds Write
CWE: [[CWE-787]]
Sources: SecurityVulnerability.io, NVD Mitigation blogIssue Summary
A critical buffer overflow vulnerability has been identified in the GNU C Library's iconv function when converting charsets to certain Chinese Extended encodings. This flaw occurs when converting strings to the ISO-2022-CN-EXT character set in versions prior to 2.40, potentially leading to application crashes or memory corruption.
Technical Key Findings
The vulnerability stems from improper boundary checks during character set conversion, allowing up to 4 bytes of overflow. This could enable attackers to execute arbitrary code or disrupt program operation by manipulating memory locations adjacent to the buffer.
Vulnerable Products
All versions of GNU C Library older than 2.40 are susceptible. (That's potentially 24 years of a buffer overflow presence in the glibc!)
Impact Assessment
The vulnerability poses a high risk, potentially affecting the confidentiality, integrity, and availability of systems utilizing the affected library versions. There is no evidence of active exploitation yet, but the severity of potential impacts warrants prompt attention.
Patches or Workaround
The GNU C Library has released patches for this vulnerability. Users are advised to update to version 2.40 or later. If you are unable to (or it's not available on your OS yet), you can mitigate this issue by disabling the affected charsets in
gconv.Check if you are vulnerable
// The first line of the linker version info should include the version of glibc (either as
GLIBCorGNU libc).ldd --version// Check if the vulnerable encodings are enabled in
iconv:iconv -l | grep -E 'CN-?EXT'If they are, you will see an output like:
ISO-2022-CN-EXT//
ISO2022CNEXT//Tags
#GNUCLibrary #CVE-2024-2961 #BufferOverflow #SecurityPatch #ISO2022CNEXT #CVE20242961 #iconv #iconvglibc
-
Hah, interesting. So we have a
glibc <=2.39exploit that can be utilised against php applications (Apache, PHP-FPM) to escalate privileges. Very interesting.Sadly we don't get more info until Charles Fol's OffensiveCon talk. I'm looking forward to it.
I really want to know and understand how a 24 years old buffer overflow bug in
iconvsurfaced now and how the buffer overflow (through 4 bytes of the ISO-2022-CN-EXT set) can be exploited to even get privilege escalation. Fascinating. -
Heap Buffer Overflow in UPX Identified
Date: March 26, 2024
CVE: To be assigned
Vulnerability Type: Buffer Errors
CWE: [[CWE-122]]
Sources: NIST VULNDB VULNDB SubmitIssue Summary
A heap buffer overflow vulnerability was identified in the [[UPX|Ultimate Packer for eXecutables]] (UPX), specifically in the commit
06b0de9c77551cd4e856d453e094d8a0b6ef0d6d. This issue occurs during the handling of certain data structures, leading to potential memory corruption. The vulnerability was discovered through fuzzing techniques using the Google OSS-Fuzz project.Technical Key findings
The vulnerability is caused by improper handling of input data, resulting in a heap buffer overflow. This overflow occurs in the handling of packed files during decompression, where the bounds of allocated heap memory are not properly checked.
Vulnerable products
- [[UPX]] version identified by commit
06b0de9c77551cd4e856d453e094d8a0b6ef0d6d.
Impact assessment
An attacker could exploit this vulnerability to execute arbitrary code on the target system or cause a denial of service through application crash, potentially compromising the system's integrity and availability.
Patches or workaround
No specific patches or workarounds were mentioned at the time of reporting. Users are advised to monitor the official [[UPX]] GitHub repository for updates.
Tags
#UPX #BufferOverflow #HeapOverflow #SecurityVulnerability #CVE
- [[UPX]] version identified by commit
-
✨Stack Overflow vulnerability in TOTOLINK LR1200GB allows remote unauthenticated attackers to bypass authentication
https://ssd-disclosure.com/ssd-advisory-totolink-lr1200gb-auth-bypass/
-
Linux: Sicherheitslücke in glibc bringt Angreifern Root-Privilegien
Fast alle aktuellen Linux-Varianten sind von dem Sicherheitsleck betroffen, das Missetäter jedoch nicht aus der Ferne angreifen können. Updates stehen bereit.
#BufferOverflow #GLIBC #IntegerOverflows #Security #Sicherheitslücken