Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
PHP HIGH 7.1
CVE-2022-31630

In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible to supply a specially crafted…

Fix: 7.4.33 / 8.0.25+
Fix from $1,950 2022-11-14
Xmm 7560 Firmware HIGH 8.1
CVE-2022-26369

Out-of-bounds read in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow a privileged user to potentially enable…

Mitigation only
Fix from $1,950 2022-11-11
Contiki Ng MEDIUM 5.4
CVE-2022-41873

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 are vulnerable to an Out-of-boun…

Fix: 4.9+
Fix from $1,600 2022-11-11
Redex CRITICAL 9.8
CVE-2022-36938

DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, pot…

Fix: 2022-11-04+
Fix from $2,300 2022-11-11
Wasmtime HIGH 7.4
CVE-2022-39392

Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocat…

Fix: 1.0.2 / 2.0.2+
Fix from $1,950 2022-11-10
Editor Lite HIGH 7.5
CVE-2022-39891

Heap overflow vulnerability in parse_pce function in libsavsaudio.so in Editor Lite prior to version 4.0.41.3 allows attacker to get information.

Fix: 4.0.41.3+
Fix from $1,950 2022-11-09
Exynos Firmware CRITICAL 9.1
CVE-2022-39881

Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of…

Mitigation only
Fix from $2,300 2022-11-09
750 8100 Firmware HIGH 8.2
CVE-2021-34567

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provo…

Fix: 18+
Fix from $1,950 2022-11-09
Android MEDIUM 5.5
CVE-2022-32602

In keyinstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no addition…

Mitigation only
Fix from $1,600 2022-11-08
Android MEDIUM 6.7
CVE-2022-21778

In vpu, there is a possible information disclosure due to an incorrect bounds check. This could lead to local escalation of privilege with System exe…

Mitigation only
Fix from $1,600 2022-11-08
Html2xhtml HIGH 8.1
CVE-2022-44311

html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo) at procesador.c. This vulner…

No fix yet
Fix from $1,950 2022-11-08
Parasolid HIGH 7.8
CVE-2022-39157

A vulnerability has been identified in Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.0 (All versions >= V34.0.252 < V34.0.254), Parasolid…

Fix: 34.0.254 / 34.1.244+
Fix from $1,950 2022-11-08
Jt2go HIGH 7.8
CVE-2022-41661

A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visu…

Fix: 13.3.0.7 / 14.0.0.3+
Fix from $1,950 2022-11-08
Jt2go HIGH 7.8
CVE-2022-41662

A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visu…

Fix: 13.3.0.7 / 14.0.0.3+
Fix from $1,950 2022-11-08
Gifdec HIGH 7.8
CVE-2022-43359

Gifdec commit 1dcbae19363597314f6623010cc80abad4e47f7c was discovered to contain an out-of-bounds read in the function read_image_data. This vulnerab…

Patch available
Fix from $1,950 2022-11-07
Wolfssl CRITICAL 9.1
CVE-2022-42905

In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can …

Fix: 5.5.2+
Fix from $2,300 2022-11-07
Sudo HIGH 7.1
CVE-2022-43995

Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-bounds error that can result in a…

Fix: 1.9.12+
Fix from $1,950 2022-11-02
macOS MEDIUM 5.5
CVE-2022-32936

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13. An app may be able to disclose kernel me…

Fix: 13.0+
Fix from $1,600 2022-11-01
Lodepng MEDIUM 5.5
CVE-2022-44081

Lodepng v20220717 was discovered to contain a segmentation fault via the function pngdetail.

No fix yet
Fix from $1,600 2022-10-31
Wabt HIGH 7.1
CVE-2022-43280

wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.

Patch available
Fix from $1,950 2022-10-28
Wabt HIGH 7.1
CVE-2022-43282

wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.

Patch available
Fix from $1,950 2022-10-28
Diagnostic Log And Trace MEDIUM 5.5
CVE-2022-39836

An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file…

Fix: after 2.18.8
Fix from $1,600 2022-10-25
Illustrator HIGH 7.8
CVE-2022-38436

Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted fil…

Fix: after 26.4
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35264

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35265

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35266

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35267

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35268

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35269

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25
R1510 Firmware HIGH 7.5
CVE-2022-35270

A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network re…

No fix yet
Fix from $1,950 2022-10-25