Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Freertos CRITICAL 9.8
CVE-2021-32020

The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.

Fix: 10.4.3+
Fix from $2,300 2021-05-03
Secure Firewall Threat Defense HIGH 8.6
CVE-2021-1402

A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote…

Fix: 6.4.0 / 6.6.0+
Fix from $1,950 2021-04-29
Solid Edge Se2020 HIGH 7.8
CVE-2020-26997

A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (All versions < SE2020MP14), Solid Edge SE202…

Mitigation only
Fix from $1,950 2021-04-22
Simotics Connect 400 Firmware HIGH 7.4
CVE-2020-27738

A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20)…

Fix: 0.5.0.0 / 4.1.0+
Fix from $1,950 2021-04-22
Junos MEDIUM 6.5
CVE-2021-0242

A vulnerability due to the improper handling of direct memory access (DMA) buffers on EX4300 switches on Juniper Networks Junos OS allows an attacker…

Mitigation only
Fix from $1,600 2021-04-22
Junos HIGH 7.5
CVE-2021-0227

An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-Web on SRX Series devices all…

Mitigation only
Fix from $1,950 2021-04-22
Jhead HIGH 7.8
CVE-2021-3496

A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.

Patch available
Fix from $1,950 2021-04-22
Debian Linux HIGH 7.8
CVE-2021-3498

GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files.

Fix: 1.18.4+
Fix from $1,950 2021-04-19
Gpac MEDIUM 5.5
CVE-2021-31261

The gf_hinter_track_new function in GPAC 1.0.1 allows attackers to read memory via a crafted file in the MP4Box command.

Patch available
Fix from $1,600 2021-04-19
G0 Firmware CRITICAL 9.8
CVE-2021-27691EPSS 25%

Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware …

Mitigation only
Fix from $2,300 2021-04-16
G1 Firmware CRITICAL 9.8
CVE-2021-27692

Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute a…

Mitigation only
Fix from $2,300 2021-04-16
Imagegear HIGH 7.8
CVE-2021-21784

An out-of-bounds write vulnerability exists in the JPG format SOF marker processing of Accusoft ImageGear 19.8. A specially crafted malformed file ca…

No fix yet
Fix from $1,950 2021-04-13
Rust HIGH 7.5
CVE-2015-20001

In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe. The binary heap is left in an inconsistent state when the comparison of g…

Fix: 1.2.0+
Fix from $1,950 2021-04-11
Rust HIGH 7.5
CVE-2021-28877

In the standard library in Rust before 1.51.0, the Zip implementation calls __iterator_get_unchecked() for the same index more than once when nested.…

Fix: 1.51.0+
Fix from $1,950 2021-04-11
Rust HIGH 7.5
CVE-2021-28878

In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the same index (under certa…

Fix: 1.52.0+
Fix from $1,950 2021-04-11
Catalyst Sd Wan Manager CRITICAL 9.8
CVE-2021-1479

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authe…

Fix: 19.2.4 / 20.3.3+
Fix from $2,300 2021-04-08
Catalyst Sd Wan Manager HIGH 7.8
CVE-2021-1480

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authe…

Fix: 19.2.4 / 20.3.3+
Fix from $1,950 2021-04-08
Rv110w Firmware CRITICAL 9.8
CVE-2021-1459

A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticate…

Mitigation only
Fix from $2,300 2021-04-08
Rv160 Firmware CRITICAL 9.8
CVE-2021-1472EPSS 72%

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbit…

Fix: 1.0.01.03 / 1.0.03.21+
Fix from $2,300 2021-04-08
Rv340 Firmware CRITICAL 9.8
CVE-2021-1473EPSS 64%

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbit…

Fix: 1.0.03.21+
Fix from $2,300 2021-04-08
Rv132w Firmware HIGH 8.8
CVE-2021-1309

Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthentica…

Mitigation only
Fix from $1,950 2021-04-08
Catalyst Sd Wan Manager HIGH 7.8
CVE-2021-1137

Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authe…

Fix: 19.2.4 / 20.3.3+
Fix from $1,950 2021-04-08
Rv132w Firmware HIGH 7.4
CVE-2021-1251

Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthentica…

Mitigation only
Fix from $1,950 2021-04-08
Rv132w Firmware HIGH 7.4
CVE-2021-1308

Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthentica…

Mitigation only
Fix from $1,950 2021-04-08
Outer Cgi CRITICAL 9.8
CVE-2021-30454

An issue was discovered in the outer_cgi crate before 0.2.1 for Rust. A user-provided Read instance receives an uninitialized memory buffer from KeyV…

Fix: 0.2.1+
Fix from $2,300 2021-04-07
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2021-22991 KEVEPSS 61%

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, undisclo…

Fix: 12.1.5.3 / 13.1.3.6+
Fix from $2,300 2021-03-31
Redis MEDIUM 5.3
CVE-2021-3470

A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allocator other than jemalloc or …

Fix: 5.0.10 / 6.0.9+
Fix from $1,600 2021-03-31
Binutils MEDIUM 5.5
CVE-2021-20284

A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the nu…

No fix yet
Fix from $1,600 2021-03-26
Upx MEDIUM 6.6
CVE-2021-20285

A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and app…

No fix yet
Fix from $1,600 2021-03-26
Arcgis Engine HIGH 7.8
CVE-2021-29097

Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) …

Fix: after 10.8.1
Fix from $1,950 2021-03-25