< ciso
brief />
Tag Banner

All news with #buffer overflow tag

55 articles

Critical Citrix NetScaler DTLS Overflow Under Active Exploitation

🔒 Researchers disclosed details of a critical memory overflow in Citrix NetScaler ADC and Gateway, tracked as CVE-2026-88772 (CVSS 9.5). The flaw stems from improper DTLS fragment parsing in the NetScaler Packet Processing Engine, allowing crafted records to overflow a scratch buffer and enable remote code execution or denial-of-service. Vendor and researchers show how reassembly of many small fragments can produce a large NSB chain, enabling shellcode execution by bypassing NX protections with mprotect().
read more →

F5 BIG‑IP APM critical OAuth RCE patched

🛡️ F5 has disclosed and patched a critical heap‑based buffer overflow, CVE-2026-94127, in BIG‑IP Access Policy Manager when it is configured as an OAuth authorization server. The vulnerability allows unauthenticated remote code execution via specially crafted traffic to a virtual server hosting an APM access policy and an OAuth authorization server profile. F5 released engineering hotfixes for affected 21.1, 17.5 and 17.1 branches and provided an iRule mitigation for cases where immediate patching is not possible.
read more →

D-Link warns of critical zero-day in DIR-822A routers

🔒 D-Link disclosed a max-severity zero-day affecting DIR-822A routers that stems from a stack-based buffer overflow in the DHCP server component and can be exploited without authentication. Attackers on the same local network can send crafted DHCP packets to crash the DHCP daemon or achieve remote code execution. The vendor noted a public proof-of-concept exploit and is investigating a second public PoC for an L2TP parser out-of-bounds write.
read more →

HPE fixes critical ArubaOS‑CX remote code flaw

🔒 HPE has released patches for a critical buffer overflow in ArubaOS‑CX (CVE-2026-73749) that lets unauthenticated attackers send crafted packets to a daemon and achieve remote code execution with elevated privileges. The vendor lists fixed builds across multiple release branches and warns that some versions have reached End of Maintenance, receiving only selective critical fixes. The bulletin also addresses 23 additional vulnerabilities ranging from high to low severity and urges customers to upgrade to the patched releases.
read more →

Zoom annotation flaws allowed zero-click takeover

🛡️ Researchers found that Zoom's annotation feature could enable zero-click remote code execution between meeting participants. The flaws affected multiple Zoom clients and SDKs and were patched in June and July, before public disclosure, with no reported exploitation at publication. The bugs involve improper parsing of structured drawing objects, leading to buffer overflows, over-reads, and a use-after-free. Patches and CVE references are included in Zoom advisories.
read more →

OpenWrt critical DHCPv6 overflow and LuCI audit fixes

🛡️ OpenWrt released 24.10.8 (and 25.12.5 for 25.12 users) to fix a critical DHCPv6 stack overflow (CVE-2026-53921) and several remotely triggerable network-service flaws enabled by default. The DHCPv6 bug lets an unauthenticated attacker reachable to UDP/547 overwrite a stack buffer in odhcpd, potentially enabling code execution on devices lacking typical mitigations. The advisory includes public PoC code; other fixes include uhttpd request-smuggling, DHCPv6 hostname-injection XSS, and LuCI component hardening still under review.
read more →

7‑Zip XZ Vulnerability Fixed in 26.02 Update

🛡️ 7‑Zip 26.02 fixes CVE-2026-14266, a heap-based buffer overflow in its XZ decoder that can lead to code execution when a crafted XZ archive is opened. ZDI disclosed the flaw on July 15 after it was reported June 5; the patch shipped June 25. Exploitation requires the victim to open a malicious file, and on Windows the code runs with 7‑Zip's process token, not elevated privileges. Users should manually update to 26.02 or later, and vendors bundling 7‑Zip must issue their own fixes.
read more →

Critical nginx heap overflow allows remote crashes

🛡️ F5 released patches for a critical nginx heap buffer overflow (CVE-2026-42533) that can crash or restart worker processes and, in some environments, enable remote code execution. Fixed versions are nginx 1.30.4 (stable), 1.31.3 (mainline), and NGINX Plus 37.0.3.1; systems on earlier releases should upgrade. The flaw occurs in the nginx script engine when a regex-based map's output variable is used in a string expression after an earlier regex capture, causing a two-pass evaluation mismatch that leads to overruns. F5 scores the flaw 9.2 (CVSS v4) and notes exposure depends on configuration rather than version alone.
read more →

F5 issues patches for two critical NGINX flaws

🛡️ F5 released updates to fix two critical vulnerabilities in NGINX Open Source that can allow remote code execution. CVE-2026-42530 is a use-after-free in the HTTP/3 QUIC module and CVE-2026-42055 is a heap-based buffer overflow affecting proxy and gRPC modules when specific directives are set. Patches are available across NGINX Open Source, NGINX Plus, Gateway Fabric, Instance Manager, WAF, DoS modules and Ingress Controller versions. Mitigations include disabling HTTP/3 for CVE-2026-42530 and adjusting ignore_invalid_headers or large_client_header_buffers settings for CVE-2026-42055.
read more →

F5 issues out‑of‑band patches for critical NGINX flaws

🔒 F5 released out-of-band updates to fix multiple NGINX vulnerabilities, including two critical flaws in the ngx_http_v3_module and ngx_http_proxy_v2/_grpc modules that can lead to DoS or code execution. The bugs cause use‑after‑free or heap buffer overflow in worker processes and affect NGINX Plus, Open Source, Gateway Fabric, and Instance Manager. Mitigations include disabling HTTP/3 and adjusting header buffer directives until patches are applied.
read more →

RSLinx Classic vulnerability advisory and mitigations

🔒 This advisory describes a stack-based buffer overflow and an out-of-bounds read in Rockwell Automation RSLinx Classic Third-Party components that can cause denial of service or enable remote code execution. Rockwell recommends upgrading to version 4.60.00 or later or applying patch BF31213 where upgrades are not possible. CISA urges minimizing network exposure, isolating control systems behind firewalls, and using secure remote access methods such as updated VPNs while performing impact analysis and risk assessments.
read more →

Hitachi Energy MACH HiDraw Heap Overflow Patch

🔒 Hitachi Energy reported a heap-based buffer overflow in MACH HiDraw XML parser where an authenticated local user can trigger memory corruption using a crafted XML file. Successful exploitation may cause application crashes (DoS) or enable arbitrary code execution. A vendor fix is available in version 9.23; contact your local account team for upgrade assistance. CISA recommends network segmentation, firewall controls, and minimizing exposure of control systems to the internet.
read more →

Critical HP Poly VoIP Flaw Enables Remote Root Access

🔒 HP has released patches for a critical buffer overflow in multiple IP conference phones in its Poly Voice line that can allow unauthenticated attackers to gain root on affected devices. The issue, tracked as CVE-2026-0826 and rated 9.2 CVSS, stems from SDP parsing when the ICE feature is enabled; administrators are advised to disable ICE if not needed. Rapid7 researchers released a Metasploit exploit demonstrating the vulnerability, and HP has issued UCS updates to remediate the affected VVX and Trio models.
read more →

XCharge C6 charger firmware and access vulnerabilities

🔒 CISA reports critical vulnerabilities in the XCharge C6 electric vehicle charging controller that could allow attackers to gain administrator rights or execute arbitrary code. A firmware update mechanism lacks signature validation, a stack-based buffer overflow exists in signal processing, and a management service exposes default credentials over the charging interface. XCharge has deployed updates for affected units; users should contact XCharge Support for details.
read more →

DICOM Heap Overflows: Orthanc, pydicom, GDCM Risks

🔍 This white paper examines DICOM parsing risks and demonstrates how malformed medical images can lead to heap overflow vulnerabilities during ingestion. It outlines a concrete case where an Orthanc server is targeted during image upload, producing an out-of-bounds write. The analysis highlights interactions between pydicom, GDCM, and Orthanc, and emphasizes the importance of robust parsing and hardening in PACS environments.
read more →

Four MediaInfoLib Heap Buffer Overflows Patched

🛡️ Cisco Talos disclosed four heap-based buffer overflow vulnerabilities in the MediaArea MediaInfoLib (v26.01) library, all of which can lead to arbitrary code execution when processing a malicious media file. The issues were found by Dimitrios Tatsis of Talos and have been patched by the vendor per Cisco’s third-party disclosure policy. Users can obtain Snort rules to detect exploitation and consult Talos for vulnerability advisories. Administrators should update MediaInfoLib to the vendor-released fixed versions promptly.
read more →

ABB Terra AC Heap Overflow Risks and Fixes

🔒 ABB reported a heap-based buffer overflow in select Terra AC EV chargers that can be triggered via crafted OCPP messages. Exploitation may allow heap pollution, denial-of-service, altered firmware behavior, or possible remote code execution; the vendor has released patched firmware versions. ABB strongly recommends avoiding unencrypted HTTP for OCPP connections and applying updates promptly to mitigate remote exploitation risks.
read more →

ABB AC500 V2 Modbus Buffer Over-read Advisory

🛡️ The advisory details a buffer over-read vulnerability in ABB AC500 V2 devices that can cause Modbus server responses to include fragments of earlier telegrams. Affected devices running older firmware may return invalid or appended data when presented with unsupported Modbus function codes. ABB issued a fix in AC500 V2 firmware version 2.5.3 (2016) and later; operators are urged to update and minimize network exposure. CISA republished the vendor advisory to raise visibility and recommends isolating control networks and using secure remote access.
read more →

ABB Terra AC Wallbox Buffer Overflow Advisory

🔒 ABB reports heap, stack and classic buffer overflow vulnerabilities in select Terra AC Wallbox firmware. An attacker who hijacks Bluetooth and crafts oversized fields could corrupt memory and potentially alter firmware behavior. ABB has released firmware version 1.8.36 (JP) to address the issues and recommends updating as soon as possible.
read more →

ABB B&R UEFI PXE Vulnerabilities and Vendor Updates

🔒 ABB B&R reported multiple vulnerabilities in the UEFI PXE implementation of affected B&R PCs and controllers. EDK2 Network Package issues include out-of-bounds reads, buffer overflows, infinite loops, and weak PRNG usage that can lead to remote code execution, DoS, DNS poisoning, or data exposure. Vendor updates are available for many product versions and users are advised to apply patches or follow mitigations.
read more →