CVE-2019-9500

CVSS v3 Score
8.3
High
CVSS v2 Score
7.9
High

Vulnerability Description

The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.

CVSS:8.3(High)

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVSS:8.3(High)

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVSS:8.4(High)

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vuln...

CVSS:8.4(High)

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVSS:8.4(High)

Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.

CVSS:8.4(High)

Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.