Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Radare2 CRITICAL 9.1
CVE-2022-1296

Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to…

Fix: 5.6.8+
Fix from $2,300 2022-04-11
Radare2 CRITICAL 9.1
CVE-2022-1297

Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers…

Fix: 5.6.8+
Fix from $2,300 2022-04-11
Mruby CRITICAL 9.8
CVE-2022-1276

Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

Fix: 3.2+
Fix from $2,300 2022-04-10
Fedora CRITICAL 9.1
CVE-2022-28805

singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer o…

Fix: 5.4.5+
Fix from $2,300 2022-04-08
Jerryscript CRITICAL 9.8
CVE-2021-43453

A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statement_sta…

Fix: after 2.4.0
Fix from $2,300 2022-04-07
Control For Beaglebone Sl HIGH 7.5
CVE-2022-22519

A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulting in a crash of the webserve…

Fix: 4.5.0.0+
Fix from $1,950 2022-04-07
Debian Linux CRITICAL 9.8
CVE-2022-24786

PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI…

Fix: after 2.12
Fix from $2,300 2022-04-06
Chrome MEDIUM 6.5
CVE-2022-0806

Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially …

Fix: 99.0.4844.51+
Fix from $1,600 2022-04-05
Chrome MEDIUM 6.5
CVE-2022-0792

Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 99.0.4844.51+
Fix from $1,600 2022-04-05
Bandizip CRITICAL 9.8
CVE-2021-26623

A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. …

Fix: 7.19+
Fix from $2,300 2022-04-01
Qemu MEDIUM 6.5
CVE-2021-20295

It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released a…

Fix: 4.2.0-34+
Fix from $1,600 2022-04-01
Radare2 MEDIUM 6.6
CVE-2022-1207

Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read sensitive information from outs…

Fix: 5.6.8+
Fix from $1,600 2022-04-01
Aqt1000 Firmware CRITICAL 9.1
CVE-2021-35088

Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Snapdragon Compute, S…

Patch available
Fix from $2,300 2022-04-01
Aqt1000 Firmware HIGH 7.8
CVE-2021-35106

Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdr…

Patch available
Fix from $1,950 2022-04-01
Apq8096au Firmware CRITICAL 9.1
CVE-2021-35117

An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdra…

Patch available
Fix from $2,300 2022-04-01
Android MEDIUM 5.5
CVE-2021-39774

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with no additional exe…

Mitigation only
Fix from $1,600 2022-03-30
Vxworks HIGH 7.5
CVE-2022-23937

In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario.

Mitigation only
Fix from $1,950 2022-03-29
Fedora MEDIUM 6.5
CVE-2022-26280

Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.

No fix yet
Fix from $1,600 2022-03-28
Libtiff MEDIUM 5.5
CVE-2022-1056

Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile l…

Patch available
Fix from $1,600 2022-03-28
Fedora HIGH 7.8
CVE-2022-27940

tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.

No fix yet
Fix from $1,950 2022-03-26
Fedora HIGH 7.8
CVE-2022-27941

tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c.

No fix yet
Fix from $1,950 2022-03-26
Fedora HIGH 7.8
CVE-2022-27942

tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.

No fix yet
Fix from $1,950 2022-03-26
Cncsoft Screeneditor MEDIUM 5.5
CVE-2021-44768

Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specific project file, which may all…

Fix: after 1.01.30
Fix from $1,600 2022-03-25
Splunk HIGH 7.5
CVE-2021-3422

The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured…

Fix: 7.3.9 / 8.0.9+
Fix from $1,950 2022-03-25
Debian Linux HIGH 7.1
CVE-2021-4156

An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricki…

Patch available
Fix from $1,950 2022-03-23
Bento4 HIGH 8.1
CVE-2022-27607

Bento4 1.6.0-639 has a heap-based buffer over-read in the AP4_HvccAtom class, a different issue than CVE-2018-14531.

No fix yet
Fix from $1,950 2022-03-21
Garageband HIGH 7.8
CVE-2022-22664

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. O…

Fix: 10.4.6 / 10.7.3+
Fix from $1,950 2022-03-18
Mac Os X HIGH 7.1
CVE-2022-22627

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update …

Fix: 10.15.7 / 11.6.5+
Fix from $1,950 2022-03-18
Xcode HIGH 7.8
CVE-2022-22601

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to …

Fix: 13.3+
Fix from $1,950 2022-03-18
Xcode HIGH 7.8
CVE-2022-22602

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to …

Fix: 13.3+
Fix from $1,950 2022-03-18