Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Ios Xe MEDIUM 6.5
CVE-2021-1352

A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker …

Mitigation only
Fix from $1,600 2021-03-24
Ios Xe CRITICAL 9.8
CVE-2021-1451

A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisco Catalyst 4500 Series Switches and Cisco Catalys…

Mitigation only
Fix from $2,300 2021-03-24
Ios Xe HIGH 8.1
CVE-2021-1433

A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on …

Mitigation only
Fix from $1,950 2021-03-24
Enterprise Linux MEDIUM 5.7
CVE-2021-3409

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pr…

Fix: after 5.2.0
Fix from $1,600 2021-03-23
Apq8009 Firmware MEDIUM 6.8
CVE-2020-11305

Integer overflow in boot due to improper length check on arguments received in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice &…

Patch available
Fix from $1,600 2021-03-17
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22709

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) D…

Fix: after 15.0.0.21041
Fix from $1,950 2021-03-11
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22710

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) D…

Fix: after 15.0.0.21041
Fix from $1,950 2021-03-11
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22711

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) D…

Fix: after 15.0.0.21041
Fix from $1,950 2021-03-11
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22712

A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) D…

Fix: after 15.0.0.21041
Fix from $1,950 2021-03-11
Powerlogic Ion8650 Firmware HIGH 7.5
CVE-2021-22713

A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION77…

Fix: 4.40.1 / 372+
Fix from $1,950 2021-03-11
Powerlogic Ion7400 Firmware CRITICAL 9.8
CVE-2021-22714

A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All…

Fix: 3.0.0+
Fix from $2,300 2021-03-11
Windows 10 HIGH 7.8
CVE-2021-26868

Windows Graphics Component Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-03-11
Hhvm HIGH 7.5
CVE-2020-1899

The unserialize() function supported a type code, "S", which was meant to be supported only for APC serialization. This type code allowed arbitrary m…

Fix: 4.32.3 / 4.56.1+
Fix from $1,950 2021-03-11
Enterprise Linux MEDIUM 5.5
CVE-2020-35521

A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of servi…

Fix: 4.2.0+
Fix from $1,600 2021-03-09
Fedora MEDIUM 5.5
CVE-2020-35522

In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service…

Fix: 4.2.0+
Fix from $1,600 2021-03-09
Debian Linux HIGH 7.5
CVE-2021-20276

A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service.

Fix: 3.0.32+
Fix from $1,950 2021-03-09
Debian Linux HIGH 7.5
CVE-2021-20275

A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.

Fix: 3.0.32+
Fix from $1,950 2021-03-09
Quinn HIGH 7.5
CVE-2021-28036

An issue was discovered in the quinn crate before 0.7.0 for Rust. It may have invalid memory access for certain versions of the standard library beca…

Fix: 0.5.4 / 0.6.2+
Fix from $1,950 2021-03-05
Enterprise Linux HIGH 7.8
CVE-2021-3404

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a h…

No fix yet
Fix from $1,950 2021-03-04
Diskstation Manager HIGH 8.1
CVE-2021-26561

Stack-based buffer overflow vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle a…

Fix: 6.2.3-25426-3+
Fix from $1,950 2021-02-26
Debian Linux HIGH 7.8
CVE-2021-3410

A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arb…

No fix yet
Fix from $1,950 2021-02-23
Keyshot HIGH 7.8
CVE-2021-22649

Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Lux…

Fix: 10.1+
Fix from $1,950 2021-02-23
Fontforge HIGH 8.8
CVE-2020-25690

An out-of-bounds write flaw was found in FontForge in versions before 20200314 while parsing SFD files containing certain LayerCount tokens. This fla…

Fix: 20200314+
Fix from $1,950 2021-02-23
Apq8009 MEDIUM 6.8
CVE-2020-11286

An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard request categories like devi…

Patch available
Fix from $1,600 2021-02-22
Aqt1000 Firmware HIGH 7.8
CVE-2020-11194

Possible out of bound access in TA while processing a command from NS side due to improper length check of response buffer in Snapdragon Auto, Snapdr…

Mitigation only
Fix from $1,950 2021-02-22
C Controller Module Setting And Monitoring Tool CRITICAL 9.8
CVE-2021-20588EPSS 7%

Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration To…

Fix: after 3.44w
Fix from $2,300 2021-02-19
Nb Connect CRITICAL 9.8
CVE-2021-27376

An issue was discovered in the nb-connect crate before 1.0.3 for Rust. It may have invalid memory access for certain versions of the standard library…

Fix: 1.0.3+
Fix from $2,300 2021-02-18
Graphics Drivers MEDIUM 5.5
CVE-2020-12365

Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may all…

Fix: 15.33.51.5146 / 15.36.39.5144+
Fix from $1,600 2021-02-17
Graphics Drivers MEDIUM 5.5
CVE-2020-12370

Untrusted pointer dereference in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a den…

Fix: 26.20.100.8141+
Fix from $1,600 2021-02-17
Bmc Firmware MEDIUM 6.7
CVE-2020-12373

Expired pointer dereference in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denia…

Fix: 2.47+
Fix from $1,600 2021-02-17