Vulnerability index

Browse CVEs

2,665 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Android CRITICAL 9.8
CVE-2021-25384

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor library prior to SMR MAY-2021 Rele…

Mitigation only
Fix from $2,300 2021-06-11
Android CRITICAL 10.0
CVE-2021-25387

An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to exec…

Mitigation only
Fix from $2,300 2021-06-11
HTTP Server CRITICAL 9.8
CVE-2021-26691EPSS 68%

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

Fix: 18.1.0.1.0+
Fix from $2,300 2021-06-10
Windows 10 HIGH 7.8
CVE-2021-31954

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Patch available
Fix from $1,950 2021-06-08
Zephyr CRITICAL 9.8
CVE-2020-10064

Improper Input Frame Validation in ieee802154 Processing. Zephyr versions >= v1.14.2, >= v2.2.0 contain Stack-based Buffer Overflow (CWE-121), Heap-b…

Fix: after 2.2.0
Fix from $2,300 2021-05-25
Zephyr HIGH 7.6
CVE-2020-13600

Malformed SPI in response for eswifi can corrupt kernel memory. Zephyr versions >= 1.14.2, >= 2.3.0 contain Heap-based Buffer Overflow (CWE-122). For…

Fix: after 2.3.0
Fix from $1,950 2021-05-25
Debian Linux HIGH 8.8
CVE-2021-31439

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authenticat…

Fix: 3.1.13 / 6.2.3-25426-3+
Fix from $1,950 2021-05-21
Foxit Reader HIGH 7.8
CVE-2021-31454

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.1.37576. User interaction is requ…

Fix: after 10.1.3.37598
Fix from $1,950 2021-05-07
Fedora HIGH 7.8
CVE-2021-29464

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was…

Fix: 0.27.4+
Fix from $1,950 2021-04-30
Parallels Desktop HIGH 8.8
CVE-2021-31424

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first …

Mitigation only
Fix from $1,950 2021-04-29
Parallels Desktop HIGH 8.2
CVE-2021-31428

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first …

Mitigation only
Fix from $1,950 2021-04-29
Parallels Desktop HIGH 8.2
CVE-2021-31429

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.5-47309. An attacker must first …

Mitigation only
Fix from $1,950 2021-04-29
Foxit Studio Photo HIGH 7.8
CVE-2021-31436

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.931. User interaction is r…

Fix: after 3.6.6.933
Fix from $1,950 2021-04-29
Scalance X200 4p Irt Firmware CRITICAL 9.8
CVE-2021-25668

A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT…

Fix: 5.2.5 / 5.5.1+
Fix from $2,300 2021-04-22
Fedora HIGH 7.8
CVE-2021-29457

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was…

Fix: 0.27.4+
Fix from $1,950 2021-04-19
Br200 Firmware HIGH 8.8
CVE-2021-27253

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Although authent…

Fix: 1.0.0.134 / 1.0.1.60+
Fix from $1,950 2021-04-14
Android CRITICAL 9.8
CVE-2021-25360

An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitrary code on …

Mitigation only
Fix from $2,300 2021-04-09
Imagemagick MEDIUM 5.5
CVE-2020-27829

A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45.

Fix: 7.0.10-45+
Fix from $1,600 2021-03-26
Arcgis Engine HIGH 7.8
CVE-2021-29097

Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) …

Fix: after 10.8.1
Fix from $1,950 2021-03-25
Daviewindy HIGH 7.8
CVE-2020-7852

DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed ex.j2c format file that is mishandled by Daview.exe. At…

Fix: after 9.0
Fix from $1,950 2021-03-24
Animate HIGH 7.8
CVE-2021-21077EPSS 8%

Adobe Animate version 21.0.3 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability. An unauthenticated attacker could leverage this…

Fix: after 21.0.3
Fix from $1,950 2021-03-12
Hhvm CRITICAL 9.8
CVE-2021-24025

Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow…

Fix: 4.56.3+
Fix from $2,300 2021-03-10
Hhvm CRITICAL 9.8
CVE-2020-1916

An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write…

Fix: 4.56.2 / 4.78.1+
Fix from $2,300 2021-03-10
Hhvm CRITICAL 9.8
CVE-2020-1917

xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated string, but was not using its stan…

Fix: 4.56.3 / 4.80.2+
Fix from $2,300 2021-03-10
Planmaker 2021 HIGH 7.8
CVE-2020-28587

A specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…

No fix yet
Fix from $1,950 2021-02-23
C Controller Module Setting And Monitoring Tool CRITICAL 9.8
CVE-2021-20587

Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and pr…

Fix: after 3.44w
Fix from $2,300 2021-02-19
Acrobat HIGH 8.8
CVE-2021-21017 KEVEPSS 86%

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a hea…

Fix: after 20.013.20074
Fix from $1,950 2021-02-11
Imagegear HIGH 8.8
CVE-2020-13572

A heap overflow vulnerability exists in the way the GIF parser decodes LZW compressed streams in Accusoft ImageGear 19.8. A specially crafted malform…

No fix yet
Fix from $1,950 2021-02-10
Planmaker 2021 HIGH 7.8
CVE-2020-13581

In SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to copy data f…

No fix yet
Fix from $1,950 2021-02-10
Planmaker 2021 HIGH 7.8
CVE-2020-27250

In SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to copy data f…

No fix yet
Fix from $1,950 2021-02-10