Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Substance 3d Stager HIGH 7.8
CVE-2023-25873

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could r…

Fix: after 2.0.0
Fix from $1,950 2023-03-27
Substance 3d Stager MEDIUM 5.5
CVE-2023-25875

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive…

Fix: after 2.0.0
Fix from $1,600 2023-03-27
Substance 3d Stager MEDIUM 5.5
CVE-2023-25876

Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive…

Fix: after 2.0.0
Fix from $1,600 2023-03-27
Enterprise Linux HIGH 7.1
CVE-2023-1380EPSS 17%

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel.…

Fix: 4.14.315 / 4.19.283+
Fix from $1,950 2023-03-27
Linux Kernel MEDIUM 5.3
CVE-2023-28866

In the Linux kernel through 6.2.8, net/bluetooth/hci_sync.c allows out-of-bounds access because amp_init1[] and amp_init2[] are supposed to have an i…

Fix: after 6.2.8
Fix from $1,600 2023-03-27
Tensorflow HIGH 7.5
CVE-2023-25658

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, an out of bounds read is in GRUBlockCellGrad. A fix …

Fix: 2.12.0+
Fix from $1,950 2023-03-25
Tensorflow HIGH 7.5
CVE-2023-25659

TensorFlow is an open source platform for machine learning. Prior to versions 2.12.0 and 2.11.1, if the parameter `indices` for `DynamicStitch` does …

Fix: 2.12.0+
Fix from $1,950 2023-03-25
Tensorflow CRITICAL 9.8
CVE-2023-25668

TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not …

Fix: 2.12.0+
Fix from $2,300 2023-03-25
Versionize HIGH 7.5
CVE-2023-28448

Versionize is a framework for version tolerant serializion/deserialization of Rust data structures, designed for usecases that need fast deserializat…

Fix: 0.1.10+
Fix from $1,950 2023-03-24
Android HIGH 7.5
CVE-2023-21053

In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote info…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.5
CVE-2023-21059

In EUTRAN_LCS_DecodeFacilityInformationElement of LPP_LcsManagement.c, there is a possible out of bounds read due to a missing bounds check. This cou…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.5
CVE-2023-21060

In sms_GetTpPiIe of sms_PduCodec.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information discl…

Mitigation only
Fix from $1,950 2023-03-24
Android MEDIUM 6.7
CVE-2023-21062

In DoSetTempEcc of imsservice.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of pr…

Mitigation only
Fix from $1,600 2023-03-24
Android MEDIUM 6.7
CVE-2023-21063

In ParseWithAuthType of simdata.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of …

Mitigation only
Fix from $1,600 2023-03-24
Android MEDIUM 6.7
CVE-2023-21064

In DoSetPinControl of miscservice.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of p…

Mitigation only
Fix from $1,600 2023-03-24
Android MEDIUM 5.5
CVE-2023-21019

In ih264e_init_proc_ctxt of ih264e_process.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informat…

Patch available
Fix from $1,600 2023-03-24
Android HIGH 7.5
CVE-2023-21028

In parse_printerAttributes of ipphelper.c, there is a possible out of bounds read due to a string without a null-terminator. This could lead to remot…

Patch available
Fix from $1,950 2023-03-24
Android MEDIUM 5.5
CVE-2023-20973

In btm_create_conn_cancel_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local info…

Mitigation only
Fix from $1,600 2023-03-24
Android MEDIUM 5.5
CVE-2023-20974

In btm_ble_add_resolving_list_entry_complete of btm_ble_privacy.cc, there is a possible out of bounds read due to a missing bounds check. This could …

Mitigation only
Fix from $1,600 2023-03-24
Android MEDIUM 5.5
CVE-2023-20979

In GetNextSourceDataPacket of bta_av_co.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local informatio…

Mitigation only
Fix from $1,600 2023-03-24
Android MEDIUM 5.5
CVE-2023-20980

In btu_ble_ll_conn_param_upd_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local infor…

Mitigation only
Fix from $1,600 2023-03-24
Android HIGH 7.1
CVE-2023-20958

In read_paint of ttcolr.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with…

Patch available
Fix from $1,950 2023-03-24
Rizin HIGH 7.8
CVE-2021-3674

A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the headers. Crafted values in th…

Fix: after 0.2.1
Fix from $1,950 2023-03-24
Deno Runtime CRITICAL 9.8
CVE-2023-28445

Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are s…

Patch available
Fix from $2,300 2023-03-24
Fedora MEDIUM 6.3
CVE-2023-1544

A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to allocate and initialize a…

Fix: after 7.2.0
Fix from $1,600 2023-03-23
Business 150ax Firmware MEDIUM 6.5
CVE-2023-20112

A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on…

Fix: 10.3.2.0+
Fix from $1,600 2023-03-23
Illustrator MEDIUM 5.5
CVE-2023-25862

Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure o…

Fix: 27.3.1+
Fix from $1,600 2023-03-22
Thinmanager HIGH 7.5
CVE-2023-27857EPSS 18%

In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field …

Fix: 11.0.5 / 11.1.5+
Fix from $1,950 2023-03-22
Chrome HIGH 8.8
CVE-2023-1532

Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 111.0.5563.110+
Fix from $1,950 2023-03-21
Chrome HIGH 8.8
CVE-2023-1534

Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentiall…

Fix: 111.0.5563.110+
Fix from $1,950 2023-03-21