Vulnerability index

Browse CVEs

2,665 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Imagemagick MEDIUM 5.5
CVE-2020-25667

TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for `"dc:format=\"image/dng\"` within `pr…

Fix: 6.9.10-69 / 7.0.9-0+
Fix from $1,600 2020-12-08
Openusd HIGH 7.8
CVE-2020-13493

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. A specially crafted USD…

No fix yet
Fix from $1,950 2020-12-02
Openusd MEDIUM 5.5
CVE-2020-13494

A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 parsing of compressed string tokens in binary USD files. A specially crafted malforme…

No fix yet
Fix from $1,600 2020-12-02
Plc Editor HIGH 8.8
CVE-2020-25181

WECON PLC Editor Versions 1.3.8 and prior has a heap-based buffer overflow vulnerabilities have been identified that may allow arbitrary code executi…

Fix: after 1.3.8
Fix from $1,950 2020-12-01
Factorytalk Linx CRITICAL 9.8
CVE-2020-27251EPSS 6%

A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacke…

Fix: after 6.11
Fix from $2,300 2020-11-26
Factorytalk Linx HIGH 7.5
CVE-2020-27255

A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacke…

Fix: after 6.11
Fix from $1,950 2020-11-26
Openusd HIGH 7.8
CVE-2020-6155

A heap overflow vulnerability exists in the Pixar OpenUSD 20.05 while parsing compressed value rep arrays in binary USD files. A specially crafted ma…

No fix yet
Fix from $1,950 2020-11-13
Openusd HIGH 7.8
CVE-2020-6156

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. To trigger this vulnera…

No fix yet
Fix from $1,950 2020-11-13
Openusd HIGH 7.8
CVE-2020-6147

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. This instance exists in…

Fix: 14.0+
Fix from $1,950 2020-11-13
Openusd HIGH 7.8
CVE-2020-6148

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. An instance exists in U…

No fix yet
Fix from $1,950 2020-11-13
Openusd HIGH 7.8
CVE-2020-6149

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. To trigger this vulnera…

No fix yet
Fix from $1,950 2020-11-13
Openusd HIGH 7.8
CVE-2020-6150

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software USDC file format SPECS section decompression heap overflow.

No fix yet
Fix from $1,950 2020-11-13
Acrobat HIGH 7.8
CVE-2020-24435EPSS 53%

Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a heap-based b…

Fix: after 20.012.20048
Fix from $1,950 2020-11-05
Chrome CRITICAL 9.6
CVE-2020-16010 KEVEPSS 6%

Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to p…

Fix: 86.0.4240.185+
Fix from $2,300 2020-11-03
Sonicos HIGH 7.5
CVE-2020-5138

A Heap Overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS) on the firewall SSLVPN service…

Fix: after 6.5.4.7
Fix from $1,950 2020-10-12
Whatsapp HIGH 7.8
CVE-2020-1906

A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could have allowed an out-of-bounds …

Fix: 2.20.46 / 2.20.130+
Fix from $1,950 2020-10-06
Tensorflow MEDIUM 5.4
CVE-2020-15198

In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tenso…

Fix: 2.3.1+
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 5.9
CVE-2020-15200

In Tensorflow before version 2.3.1, the `RaggedCountSparseOutput` implementation does not validate that the input arguments form a valid ragged tenso…

Patch available
Fix from $1,600 2020-09-25
Tensorflow CRITICAL 9.8
CVE-2020-15205

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This a…

Fix: 1.15.4 / 2.0.3+
Fix from $2,300 2020-09-25
Tensorflow HIGH 8.8
CVE-2020-15195

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the implementation of `SparseFillEmptyRowsGrad` uses a double indexing pattern. …

Fix: 1.15.4 / 2.0.3+
Fix from $1,950 2020-09-25
Tensorflow CRITICAL 9.9
CVE-2020-15196

In Tensorflow version 2.3.0, the `SparseCountSparseOutput` and `RaggedCountSparseOutput` implementations don't validate that the `weights` tensor has…

Patch available
Fix from $2,300 2020-09-25
Nitro Pro HIGH 8.8
CVE-2020-6146EPSS 77%

An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents…

No fix yet
Fix from $1,950 2020-09-16
Libiec61850 CRITICAL 9.8
CVE-2020-15158

In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leadin…

Fix: 1.4.3+
Fix from $2,300 2020-08-26
Opc CRITICAL 9.8
CVE-2020-14524

Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer ove…

Fix: 4.47.0+
Fix from $2,300 2020-08-25
Tpeditor HIGH 7.8
CVE-2020-16223

Delta Electronics TPEditor Versions 1.97 and prior. A heap-based buffer overflow may be exploited by processing a specially crafted project file. Suc…

Fix: after 1.97
Fix from $1,950 2020-08-07
Webaccess\/hmi Designer HIGH 7.8
CVE-2020-16207

Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by opening specia…

Fix: after 2.1.9.31
Fix from $1,950 2020-08-06
Enterprise Linux MEDIUM 6.0
CVE-2020-14310

There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in byt…

Fix: 2.06+
Fix from $1,600 2020-07-31
Enterprise Linux MEDIUM 6.0
CVE-2020-14311

There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode siz…

Fix: 2.06+
Fix from $1,600 2020-07-31
Daviewindy HIGH 7.8
CVE-2020-7828

DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mish…

Fix: after 8.98.4
Fix from $1,950 2020-07-30
Daviewindy HIGH 7.8
CVE-2020-7829

DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mish…

Fix: after 8.98.4
Fix from $1,950 2020-07-30