Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Acrobat Dc MEDIUM 5.5
CVE-2022-28251

Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read…

Fix: after 22.001.20085
Fix from $1,600 2022-05-11
Acrobat Dc MEDIUM 5.5
CVE-2022-28253

Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read…

Fix: after 22.001.20085
Fix from $1,600 2022-05-11
Acrobat Dc HIGH 7.8
CVE-2022-28239

Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read…

Fix: after 22.001.20085
Fix from $1,950 2022-05-11
Acrobat Dc HIGH 7.8
CVE-2022-28231

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by an out-of-bounds read…

Fix: after 22.001.20085
Fix from $1,950 2022-05-11
Mp3gain CRITICAL 9.8
CVE-2021-34085

Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a deni…

Fix: 1.5.2+
Fix from $2,300 2022-05-11
Epyc 7232p Firmware MEDIUM 5.5
CVE-2021-26388

Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory conten…

Mitigation only
Fix from $1,600 2022-05-11
Fedora MEDIUM 5.5
CVE-2022-1622

LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted …

Fix: 9.0 / 11.7+
Fix from $1,600 2022-05-11
Fedora MEDIUM 5.5
CVE-2022-1623

LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted …

Patch available
Fix from $1,600 2022-05-11
Android MEDIUM 6.5
CVE-2022-20010

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote informati…

Patch available
Fix from $1,600 2022-05-10
Fedora HIGH 7.8
CVE-2022-1629

Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, M…

Fix: 8.2.4925 / 13.0+
Fix from $1,950 2022-05-10
Ruby HIGH 7.5
CVE-2022-28739

There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float convers…

Fix: 2.6.10 / 2.7.6+
Fix from $1,950 2022-05-09
Debian Linux HIGH 8.1
CVE-2018-25033

ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh…

Fix: after 0.98.4
Fix from $1,950 2022-05-08
Photoshop HIGH 7.8
CVE-2022-28274

Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted fil…

Fix: after 23.2.2
Fix from $1,950 2022-05-06
Android MEDIUM 5.5
CVE-2022-28785

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary deni…

Mitigation only
Fix from $1,600 2022-05-03
Android MEDIUM 5.5
CVE-2022-28786

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary deni…

Mitigation only
Fix from $1,600 2022-05-03
Android MEDIUM 5.5
CVE-2022-28787

Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary deni…

Mitigation only
Fix from $1,600 2022-05-03
Android MEDIUM 5.5
CVE-2022-28788

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary deni…

Mitigation only
Fix from $1,600 2022-05-03
Android MEDIUM 5.5
CVE-2022-20092

In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additi…

Mitigation only
Fix from $1,600 2022-05-03
Sound Exchange CRITICAL 9.1
CVE-2021-3643

A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a …

Mitigation only
Fix from $2,300 2022-05-02
Asda Soft HIGH 7.1
CVE-2022-1402

ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds rea…

Fix: after 5.4.1.0
Fix from $1,950 2022-04-29
Libmobi HIGH 7.8
CVE-2022-1533

Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. This vulnerability is capable of arbitrary code execution.

Fix: 0.11+
Fix from $1,950 2022-04-29
Libmobi HIGH 7.1
CVE-2022-1534

Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of…

Fix: 0.11+
Fix from $1,950 2022-04-29
Debian Linux HIGH 7.8
CVE-2022-1441

MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the fu…

Patch available
Fix from $1,950 2022-04-25
Radare2 HIGH 7.1
CVE-2022-1451

Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program r…

Fix: 5.7.0+
Fix from $1,950 2022-04-24
Radare2 HIGH 7.1
CVE-2022-1452

Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the progra…

Fix: 5.7.0+
Fix from $1,950 2022-04-24
Mruby HIGH 7.8
CVE-2022-1427

Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being explo…

Fix: 3.2+
Fix from $1,950 2022-04-23
Fedora HIGH 7.5
CVE-2022-27405

FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.

Fix: 2.12.0+
Fix from $1,950 2022-04-22
Fedora HIGH 7.5
CVE-2022-27406

FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.

Fix: 2.12.0+
Fix from $1,950 2022-04-22
Gpac MEDIUM 5.5
CVE-2022-29537

gp_rtp_builder_do_hevc in ietf/rtp_pck_mpeg4.c in GPAC 2.0.0 has a heap-based buffer over-read, as demonstrated by MP4Box.

No fix yet
Fix from $1,600 2022-04-20
Debian Linux HIGH 7.1
CVE-2022-29458

ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo libra…

Fix: 6.3 / 13.0+
Fix from $1,950 2022-04-18