๐จ CVE-2025-50644
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50645
A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_list_opt.asp endpoint is manipulated. By sending a crafted request with an excessively large value for the s parameter, an attacker can trigger a buffer overflow condition.
๐@cveNotify
A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_list_opt.asp endpoint is manipulated. By sending a crafted request with an excessively large value for the s parameter, an attacker can trigger a buffer overflow condition.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50646
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_type_asp.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_type_asp.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50647
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50648
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50649
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shut_set.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shut_set.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50650
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameter in the /router.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameter in the /router.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50652
An issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id parameter in the /saveparm_usb.asp endpoint.
๐@cveNotify
An issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id parameter in the /saveparm_usb.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50653
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /time_group.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /time_group.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50654
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thd_member.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thd_member.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50655
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50657
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50659
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50660
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50662
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50663
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50664
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, mem, pri, and attr.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, mem, pri, and attr.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50665
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request via the name, en, time, mem_gb2312, and mem_utf8 parameters.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request via the name, en, time, mem_gb2312, and mem_utf8 parameters.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50666
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parameters such as name, en, user_id, log, and time.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parameters such as name, en, user_id, log, and time.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2026-27308
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
๐@cveNotify
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
๐@cveNotify
Adobe
Adobe Security Bulletin
Security updates available for Adobe ColdFusion | APSB26-38
๐จ CVE-2026-33018
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free vulnerability via the load_gif() function in fromgif.c, where a single sixel_frame_t object is reused across all frames of an animated GIF and gif_init_frame() unconditionally frees and reallocates frame->pixels between frames without consulting the object's reference count. Because the public API explicitly provides sixel_frame_ref() to retain a frame and sixel_frame_get_pixels() to access the raw pixel buffer, a callback following this documented usage pattern will hold a dangling pointer after the second frame is decoded, resulting in a heap use-after-free confirmed by ASAN. Any application using sixel_helper_load_image_file() with a multi-frame callback to process user-supplied animated GIFs is affected, with a reliable crash as the minimum impact and potential for code execution. This issue has been fixed in version 1.8.7-r1.
๐@cveNotify
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-After-Free vulnerability via the load_gif() function in fromgif.c, where a single sixel_frame_t object is reused across all frames of an animated GIF and gif_init_frame() unconditionally frees and reallocates frame->pixels between frames without consulting the object's reference count. Because the public API explicitly provides sixel_frame_ref() to retain a frame and sixel_frame_get_pixels() to access the raw pixel buffer, a callback following this documented usage pattern will hold a dangling pointer after the second frame is decoded, resulting in a heap use-after-free confirmed by ASAN. Any application using sixel_helper_load_image_file() with a multi-frame callback to process user-supplied animated GIFs is affected, with a reliable crash as the minimum impact and potential for code execution. This issue has been fixed in version 1.8.7-r1.
๐@cveNotify
GitHub
Release v1.8.7-r1 security update ยท saitoha/libsixel
More than seven months have passed since our last release, so we are publishing this minor update. Thank you to everyone who submitted bug reports and security advisories.
Development is currently ...
Development is currently ...