home.social

#bufferoverflow — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bufferoverflow, aggregated by home.social.

fetched live
  1. CVE-2026-54212: CRITICAL buffer overflow in Tobit TeamDavid Webbox API (≤ Rollout 524). Crafted JSON lets unauthenticated attackers crash servers; RCE possible if combined with other flaws. Restrict API, monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #CVE #bufferOverflow #infosec

  2. 🔍 HIGH severity: Buffer overflow in GALAYOU Y4 v1.0.0 (CVE-2026-12192). Exploitable via local network — no patch or vendor response yet. Restrict network access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #BufferOverflow

  3. CVE-2026-9360: HIGH severity buffer overflow in Edimax EW-7438RPn v1.28a. Remotely exploitable, public exploit released, no patch yet. Disable remote access or isolate! Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #BufferOverflow

  4. 🚨 HIGH severity (CVSS 8.7): Edimax EW-7438RPn v1.0 – 1.31 stack-based buffer overflow in /goform/mp (webs arg). Remote code execution possible, public exploit out. No vendor patch. Restrict device access! CVE-2026-9348 radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #BufferOverflow

  5. Palo Alto Networks Exploits Critical PAN-OS Flaw in Limited Attacks

    Palo Alto Networks has patched a critical flaw in its PAN-OS software, CVE-2026-0300, which allowed hackers to execute malicious code with root privileges - and the company says it's already been exploited in targeted attacks. The vulnerability, a buffer overflow in the User-ID Authentication Portal service, could be triggered by…

    osintsights.com/palo-alto-netw

    #Panos #Cve20260300 #PaloAltoNetworks #BufferOverflow #Exploitation

  6. Palo Alto Networks Discloses Active Exploitation of PAN-OS Flaw Enabling Espionage

    Palo Alto Networks has uncovered active exploitation of a high-severity flaw in PAN-OS software, allowing attackers to execute arbitrary code with root privileges and inject shellcode into vulnerable systems. This critical vulnerability, tracked as CVE-2026-0300, enables unauthenticated remote code execution,…

    osintsights.com/palo-alto-netw

    #Panos #Cve20260300 #RemoteCodeExecution #BufferOverflow #PaloAltoNetworks

  7. Palo Alto Networks Discloses Zero-Day Flaw in PAN-OS Software

    Palo Alto Networks has issued a warning about a zero-day flaw in its PAN-OS software, tracked as CVE-2026-0300, which allows unauthenticated remote code execution with root privileges. This buffer overflow vulnerability in the User-ID Authentication Portal poses a high risk to PA-Series and VM-Series firewalls.

    osintsights.com/palo-alto-netw

    #ZeroDay #Cve20260300 #Panos #PaloAltoNetworks #BufferOverflow

  8. Palo Alto Networks Flaw Exploited for Remote Code Execution

    A critical vulnerability in Palo Alto Networks' PAN-OS software has been exploited, allowing hackers to execute malicious code with root privileges on firewalls - and all it takes is a few specially crafted packets. This buffer overflow flaw, tracked as CVE-2026-0300, puts PA-Series and VM-Series firewalls at risk of remote code…

    osintsights.com/palo-alto-netw

    #PaloAltoNetworks #RemoteCodeExecution #Cve20260300 #BufferOverflow #Panos

  9. 🛑 HIGH severity: Buffer overflow in Tenda F456 (v1.0.0.5) via /goform/P2pListFilter ('menufacturer/Go'). Public exploit available, no patch. Limit exposure & monitor systems. CVE-2026-7019. radar.offseq.com/threat/cve-20 #OffSeq #Tenda #Vuln #BufferOverflow

  10. ⚠️ HIGH-severity buffer overflow (CVE-2026-6560) in H3C Magic B0 (100R002) allows remote code execution or DoS via Edit_BasicSSID in /goform/aspForm. No patch yet; restrict access & monitor updates. radar.offseq.com/threat/cve-20 #OffSeq #H3C #Vuln #BufferOverflow

  11. ⚠️ HIGH severity: CVE-2026-4535 in Tenda FH451 (v1.0.0.9) — stack-based buffer overflow in /goform/WrlclientSet. Remote, unauthenticated code execution possible. Patch or mitigate now! radar.offseq.com/threat/cve-20 #OffSeq #vulnerability #IoT #bufferOverflow

  12. ⚠️ HIGH severity: CVE-2026-4535 in Tenda FH451 (v1.0.0.9) — stack-based buffer overflow in /goform/WrlclientSet. Remote, unauthenticated code execution possible. Patch or mitigate now! radar.offseq.com/threat/cve-20 #OffSeq #vulnerability #IoT #bufferOverflow

  13. 🚨 CVE-2026-4529: HIGH severity stack-based buffer overflow in D-Link DHP-1320 (1.00WWB04) via SOAP Handler. Public exploit out. Device is EOL, no patch — isolate or replace now! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #DLink #BufferOverflow #InfoSec

  14. ⚠️ CVE-2026-2086: HIGH-severity buffer overflow in UTT HiPER 810G (≤1.7.7-171114). Remote code execution possible, public exploit exists, no patch. Segment networks, disable remote mgmt, monitor for attacks. radar.offseq.com/threat/cve-20 #OffSeq #UTT #Infosec #BufferOverflow

  15. Krytyczna podatność (CVSS 9.8/10.0) w popularnym pakiecie do monitorowania urządzeń – Net-SNMP

    W popularnym pakiecie Net-SNMP, służącym do monitorowania i zarządzania urządzeniami sieciowymi wykryto krytyczną lukę bezpieczeństwa typu stack based buffer overflow. Podatność została znaleziona przez badacza bezpieczeństwa buddurid oraz zgłoszona w ramach programu Trend Micro Zero Day Initiative (ZDI). TLDR: Dla osób spotykających się z tym programem po raz pierwszy krótkie wyjaśnienie....

    #WBiegu #BufferOverflow #DoS #Podatność

    sekurak.pl/krytyczna-podatnosc

  16. Krytyczna podatność (CVSS 9.8/10.0) w popularnym pakiecie do monitorowania urządzeń – Net-SNMP

    W popularnym pakiecie Net-SNMP, służącym do monitorowania i zarządzania urządzeniami sieciowymi wykryto krytyczną lukę bezpieczeństwa typu stack based buffer overflow. Podatność została znaleziona przez badacza bezpieczeństwa buddurid oraz zgłoszona w ramach programu Trend Micro Zero Day Initiative (ZDI). TLDR: Dla osób spotykających się z tym programem po raz pierwszy krótkie wyjaśnienie....

    #WBiegu #BufferOverflow #DoS #Podatność

    sekurak.pl/krytyczna-podatnosc

  17. The SQL Slammer worm was the fastest spreading malware in Internet history. It exploited a buffer overflow vulnerability in Windows systems and could be transmitted and executed with minimal latency. Today, it is considered the precursor of ransomware and spyware attacks.

    #SQLslammerWorm #computerWorms, #malware #bufferOverflow #vulnerabilities #cybersecurity #cyberattacks

    negativepid.blog/the-sql-slamm
    negativepid.blog/the-sql-slamm

  18. 🚨 CVE-2025-14534: CRITICAL buffer overflow in UTT 进取 512W (≤3.1.7.7-171114). Remote, unauthenticated exploit — public code available. Isolate & restrict /goform/formNatStaticMap now! radar.offseq.com/threat/cve-20 #OffSeq #CVE #BufferOverflow #NetworkSecurity

  19. The SQL Slammer worm was the fastest spreading malware in Internet history. It exploited a buffer overflow vulnerability in Windows systems and could be transmitted and executed with minimal latency. Today, it is considered the precursor of ransomware and spyware attacks.

    #SQLslammerWorm #computerWorms, #malware #bufferOverflow #vulnerabilities #cybersecurity #cyberattacks

    negativepid.blog/the-sql-slamm
    negativepid.blog/the-sql-slamm

  20. ⚠️ CVE-2025-14196 (HIGH, CVSS 8.7): Remote buffer overflow in H3C Magic B1 (≤100R004). Public exploit available, no patch. Isolate devices, restrict access, monitor for /goform/aspForm attacks. radar.offseq.com/threat/cve-20 #OffSeq #H3C #BufferOverflow #Vuln

  21. The SQL Slammer worm was the fastest spreading malware in Internet history. It exploited a buffer overflow vulnerability in Windows systems and could be transmitted and executed with minimal latency. Today, it is considered the precursor of ransomware and spyware attacks.

    #SQLslammerWorm #computerWorms, #malware #bufferOverflow #vulnerabilities #cybersecurity #cyberattacks

    negativepid.blog/the-sql-slamm
    negativepid.blog/the-sql-slamm

  22. The SQL Slammer worm was the fastest spreading malware in Internet history. It exploited a buffer overflow vulnerability in Windows systems and could be transmitted and executed with minimal latency. Today, it is considered the precursor of ransomware and spyware attacks.

    #SQLslammerWorm #computerWorms, #malware #bufferOverflow #vulnerabilities #cybersecurity #cyberattacks

    negativepid.blog/the-sql-slamm
    negativepid.blog/the-sql-slamm

  23. 🛡️ CVE-2025-13258: HIGH severity buffer overflow in Tenda AC20 routers (≤16.03.08.12) via /goform/WifiExtraSet. Public exploit out—remotely exploitable, no auth needed. Restrict access, monitor, and patch ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE2025 #Tenda #BufferOverflow

  24. The SQL Slammer worm was the fastest spreading malware in Internet history. It exploited a buffer overflow vulnerability in Windows systems and could be transmitted and executed with minimal latency. Today, it is considered the precursor of ransomware and spyware attacks.

    #SQLslammerWorm #computerWorms, #malware #bufferOverflow #vulnerabilities #cybersecurity #cyberattacks

    negativepid.blog/the-sql-slamm
    negativepid.blog/the-sql-slamm

  25. "There are no workarounds that address this vulnerability.", not a quote you want to read about your fleet of Cisco devices running IOS and IOS XE Software! You must patch!

    Cisco devices have been under attack due to zero-day critical RCE flaws as detailed in CVE-2025-20333, CVE-2025-20363, and CVE-2025-20362, resulting in a denial of service (DoS) condition.

    sec.cloudapps.cisco.com/securi #Cisco #CitrixIOS #Networks #CyberAttack #CyberSecurity #DDOS #bufferoverflow #CISA

  26. "There are no workarounds that address this vulnerability.", not a quote you want to read about your fleet of Cisco devices running IOS and IOS XE Software! You must patch!

    Cisco devices have been under attack due to zero-day critical RCE flaws as detailed in CVE-2025-20333, CVE-2025-20363, and CVE-2025-20362, resulting in a denial of service (DoS) condition.

    sec.cloudapps.cisco.com/securi

  27. Chińskie kamery z krytycznymi podatnościami – Dahua Hero C1 i inne

    Rumuńska firma Bitdefender opublikowała broszurę, w której informuje o załatanych niedawno podatnościach odnalezionych w kamerach chińskiego producenta Dahua. Badacze zaznaczają, że podczas wewnętrznego audytu firmy wytwarzającej te kamery ujawniono dłuższą listę podatnych urządzeń. Użytkownicy modeli: oraz (wszystkie firmware wydane przed 16.04.2025) powinni jak najszybciej dokonać aktualizacji urządzeń.  Wykryte podatności to...

    #WBiegu #BufferOverflow #Cve #Dahua #Kamery #Podatność

    sekurak.pl/chinskie-kamery-z-k

  28. Chińskie kamery z krytycznymi podatnościami – Dahua Hero C1 i inne

    Rumuńska firma Bitdefender opublikowała broszurę, w której informuje o załatanych niedawno podatnościach odnalezionych w kamerach chińskiego producenta Dahua. Badacze zaznaczają, że podczas wewnętrznego audytu firmy wytwarzającej te kamery ujawniono dłuższą listę podatnych urządzeń. Użytkownicy modeli: oraz (wszystkie firmware wydane przed 16.04.2025) powinni jak najszybciej dokonać aktualizacji urządzeń.  Wykryte podatności to...

    #WBiegu #BufferOverflow #Cve #Dahua #Kamery #Podatność

    sekurak.pl/chinskie-kamery-z-k

  29. @byorgey for some reason I feel like I have to add, the reason Python is better than C is that you don't have to know the definition of the word "pointer". There really isn't any other reason. Don't touch that! It uses pointers!

    (ok, I don't mind not using curly braces)
    (p.s. check out the etymology of "cat" in Linux)

    #bufferOverflow

  30. #Ubuntu #Linux #mtr report mode is still #broken causes #bufferoverflow
    Start: 2024-10-07T09:46:22+0000
    *** buffer overflow detected ***: terminated
  31. Można bez uwierzytelnienia przejmować pewne routery / urządzenia WiFi. Zobacz podatność CVE-2024-20017

    Pokazał się detaliczny opis podatności oraz exploit. Luka występuje w chipsecie MediaTek MT6890, MT7915, MT7916, MT7981, MT7986 (a dokładniej w oprogramowaniu, które jest do niego dołączane przez producenta , a jeszcze dokładniej w linuksowym wappd). Przykładowy exploit został pokazany dla Netgear WAX206. Producent w opisie łatki podaje taką informację: In...

    #WBiegu #BufferOverflow #Exploit #Rce #Wifi

    sekurak.pl/mozna-bez-uwierzyte

  32. My understanding of the #CrowdStrike root cause:

    They pushed out a defective "Channel file" (some kind of config?) to #FalconSensor customers. This gets uploaded to CrowdStrike's Windows kernel module, which fails to perform correct bounds checking. The resulting #BufferOverflow results in a crash of the kernel module and thus the entire system. Correct?
    #BSOD

  33. Just realised that the code I wrote which contains a if you compile it for a 256 bit CPU is also not . Truly I am an awful person.

  34. Buffer Overflow in GNU C Library Affects Older Versions

    Date: April 17, 2024

    CVE: CVE-2024-2961

    Vulnerability Type: Out-of-bounds Write

    CWE: [[CWE-787]]

    Sources: SecurityVulnerability.io, NVD Mitigation blog

    Issue Summary

    A critical buffer overflow vulnerability has been identified in the GNU C Library's iconv function when converting charsets to certain Chinese Extended encodings. This flaw occurs when converting strings to the ISO-2022-CN-EXT character set in versions prior to 2.40, potentially leading to application crashes or memory corruption.

    Technical Key Findings

    The vulnerability stems from improper boundary checks during character set conversion, allowing up to 4 bytes of overflow. This could enable attackers to execute arbitrary code or disrupt program operation by manipulating memory locations adjacent to the buffer.

    Vulnerable Products

    All versions of GNU C Library older than 2.40 are susceptible. (That's potentially 24 years of a buffer overflow presence in the glibc!)

    Impact Assessment

    The vulnerability poses a high risk, potentially affecting the confidentiality, integrity, and availability of systems utilizing the affected library versions. There is no evidence of active exploitation yet, but the severity of potential impacts warrants prompt attention.

    Patches or Workaround

    The GNU C Library has released patches for this vulnerability. Users are advised to update to version 2.40 or later. If you are unable to (or it's not available on your OS yet), you can mitigate this issue by disabling the affected charsets in gconv.

    Check if you are vulnerable

    // The first line of the linker version info should include the version of glibc (either as GLIBC or GNU libc).

    ldd --version

    // Check if the vulnerable encodings are enabled in iconv:

    iconv -l | grep -E 'CN-?EXT'

    If they are, you will see an output like:

    ISO-2022-CN-EXT//
    ISO2022CNEXT//

    Tags

    #GNUCLibrary #CVE-2024-2961 #BufferOverflow #SecurityPatch #ISO2022CNEXT #CVE20242961 #iconv #iconvglibc

  35. Hah, interesting. So we have a glibc <=2.39 exploit that can be utilised against php applications (Apache, PHP-FPM) to escalate privileges. Very interesting.

    Sadly we don't get more info until Charles Fol's OffensiveCon talk. I'm looking forward to it.

    I really want to know and understand how a 24 years old buffer overflow bug in iconv surfaced now and how the buffer overflow (through 4 bytes of the ISO-2022-CN-EXT set) can be exploited to even get privilege escalation. Fascinating.

    openwall.com/lists/oss-securit

    #security #BufferOverflow #php #iconvglibc

  36. Heap Buffer Overflow in UPX Identified

    Date: March 26, 2024
    CVE: To be assigned
    Vulnerability Type: Buffer Errors
    CWE: [[CWE-122]]
    Sources: NIST VULNDB VULNDB Submit

    Issue Summary

    A heap buffer overflow vulnerability was identified in the [[UPX|Ultimate Packer for eXecutables]] (UPX), specifically in the commit 06b0de9c77551cd4e856d453e094d8a0b6ef0d6d. This issue occurs during the handling of certain data structures, leading to potential memory corruption. The vulnerability was discovered through fuzzing techniques using the Google OSS-Fuzz project.

    Technical Key findings

    The vulnerability is caused by improper handling of input data, resulting in a heap buffer overflow. This overflow occurs in the handling of packed files during decompression, where the bounds of allocated heap memory are not properly checked.

    Vulnerable products

    • [[UPX]] version identified by commit 06b0de9c77551cd4e856d453e094d8a0b6ef0d6d.

    Impact assessment

    An attacker could exploit this vulnerability to execute arbitrary code on the target system or cause a denial of service through application crash, potentially compromising the system's integrity and availability.

    Patches or workaround

    No specific patches or workarounds were mentioned at the time of reporting. Users are advised to monitor the official [[UPX]] GitHub repository for updates.

    Tags

    #UPX #BufferOverflow #HeapOverflow #SecurityVulnerability #CVE