Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Notes HIGH 7.1
CVE-2021-25492

Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read.

Fix: after 4.3.02.61
Fix from $1,950 2021-10-06
Notes HIGH 7.1
CVE-2021-25493

Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read

Fix: after 4.3.02.61
Fix from $1,950 2021-10-06
Notes HIGH 7.8
CVE-2021-25494

A possible buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execut…

Fix: 4.3.02.61+
Fix from $1,950 2021-10-06
Android MEDIUM 5.5
CVE-2021-0689

In RGB_to_BGR1_portable of SkSwizzler_opts.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local informat…

Patch available
Fix from $1,600 2021-10-06
Gclib HIGH 8.8
CVE-2021-42006

An out-of-bounds access in GffLine::GffLine in gff.cpp in GCLib 0.12.7 allows an attacker to cause a segmentation fault or possibly have unspecified …

Patch available
Fix from $1,950 2021-10-04
PHP MEDIUM 5.9
CVE-2021-21704

In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server c…

Fix: 7.3.29 / 7.4.21+
Fix from $1,600 2021-10-04
Coreldraw 2020 MEDIUM 5.5
CVE-2021-38107

CdrCore.dll in Corel DrawStandard 2020 22.0.0.474 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated …

Mitigation only
Fix from $1,600 2021-10-02
Wordperfect 2020 MEDIUM 5.5
CVE-2021-38108

Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthent…

Mitigation only
Fix from $1,600 2021-10-02
Coreldraw 2020 MEDIUM 5.5
CVE-2021-38109

Corel DrawStandard 2020 22.0.0.474 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated attacker could …

Mitigation only
Fix from $1,600 2021-10-02
Presentations 2020 MEDIUM 5.5
CVE-2021-38102

IPPP82.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated …

Mitigation only
Fix from $1,600 2021-10-01
Presentations 2020 MEDIUM 5.5
CVE-2021-38105

IPPP82.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated …

Mitigation only
Fix from $1,600 2021-10-01
Presentations 2020 MEDIUM 5.5
CVE-2021-38106

UAX200.dll in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated …

Mitigation only
Fix from $1,600 2021-10-01
Presentations 2020 MEDIUM 5.5
CVE-2021-38104

IPPP72.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An unauthenticated …

Mitigation only
Fix from $1,600 2021-10-01
Acrobat Dc MEDIUM 5.5
CVE-2021-39861

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-boun…

Fix: after 21.005.20060
Fix from $1,600 2021-09-29
Debian Linux MEDIUM 5.5
CVE-2021-40716

XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.…

Fix: after 2021.07
Fix from $1,600 2021-09-29
Indesign HIGH 7.8
CVE-2021-39821

Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) are affected by an out-of-bounds read vulnerability that could result in arbitra…

Fix: after 16.3.2
Fix from $1,950 2021-09-29
Irfanview MEDIUM 5.5
CVE-2021-29358

A buffer overflow vulnerability in FORMATS!ReadPVR_W+0xfa of Irfanview 4.57 allows attackers to cause a denial of service (DOS) via a crafted PVR fil…

Mitigation only
Fix from $1,600 2021-09-28
Libressl MEDIUM 5.5
CVE-2021-41581

x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buffer over-read. When the input …

Fix: after 3.4.0
Fix from $1,600 2021-09-24
Ffmpeg MEDIUM 6.5
CVE-2020-20902

A CWE-125: Out-of-bounds read vulnerability exists in long_term_filter function in g729postfilter.c in FFmpeg 4.2.1 during computation of the denomin…

Patch available
Fix from $1,600 2021-09-20
Wasmtime MEDIUM 6.3
CVE-2021-39218

Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.26.0 and before version 0.30.0 is affected by a memory unsoundn…

Fix: 0.30.0+
Fix from $1,600 2021-09-17
Debian Linux MEDIUM 5.5
CVE-2020-21535

fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.

No fix yet
Fix from $1,600 2021-09-16
HTTP Server HIGH 7.5
CVE-2021-36160EPSS 63%

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Ser…

Fix: 2.4.49+
Fix from $1,950 2021-09-16
Navisworks HIGH 7.8
CVE-2021-40155

A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the DWG f…

Mitigation only
Fix from $1,950 2021-09-15
Navisworks HIGH 7.8
CVE-2021-27045

A maliciously crafted PDF file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the PDF f…

Mitigation only
Fix from $1,950 2021-09-15
Fbx Review HIGH 7.8
CVE-2021-27044

A Out-Of-Bounds Read/Write Vulnerability in Autodesk FBX Review version 1.4.0 may lead to remote code execution through maliciously crafted DLL files…

Patch available
Fix from $1,950 2021-09-15
Fusion HIGH 8.4
CVE-2020-3960

VMware ESXi (6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) …

Fix: 11.5.5 / 15.5.5+
Fix from $1,950 2021-09-15
Libsixel MEDIUM 6.5
CVE-2020-21049

An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.

Fix: 1.8.5+
Fix from $1,600 2021-09-14
Nx 1980 HIGH 7.1
CVE-2021-37203

A vulnerability has been identified in NX 1980 Series (All versions < V1984), Solid Edge SE2021 (All versions < SE2021MP8). The plmxmlAdapterIFC.dll …

Fix: 1984+
Fix from $1,950 2021-09-14
Android MEDIUM 5.5
CVE-2021-25454

OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.

Mitigation only
Fix from $1,600 2021-09-09
Android MEDIUM 5.5
CVE-2021-25456

OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via for…

Mitigation only
Fix from $1,600 2021-09-09