Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Chrome HIGH 8.1
CVE-2021-30511

Out of bounds read in Tab Groups in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to…

Fix: 90.0.4430.212+
Fix from $1,950 2021-06-04
Linux Kernel HIGH 7.8
CVE-2021-3490EPSS 27%

The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned int…

Fix: 5.10.37 / 5.11.21+
Fix from $1,950 2021-06-04
Pillow CRITICAL 9.1
CVE-2021-25287

An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.

Fix: 8.2.0+
Fix from $2,300 2021-06-02
Pillow CRITICAL 9.1
CVE-2021-25288

An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.

Fix: 8.2.0+
Fix from $2,300 2021-06-02
Openjdk MEDIUM 5.5
CVE-2021-3522EPSS 5%

GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.

Fix: 1.18.4+
Fix from $1,600 2021-06-02
Nss CRITICAL 9.1
CVE-2020-12403

A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-b…

Fix: 3.55+
Fix from $2,300 2021-05-27
Crosscadware HIGH 7.8
CVE-2021-27490

Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior are vulne…

Fix: after 2021.1
Fix from $1,950 2021-05-27
Gattlib CRITICAL 9.8
CVE-2021-33590

GattLib 0.3-rc1 has a stack-based buffer over-read in get_device_path_from_mac in dbus/gattlib.c.

No fix yet
Fix from $2,300 2021-05-27
Dmg2img HIGH 7.1
CVE-2021-32614

A flaw was found in dmg2img through 20170502. fill_mishblk() does not check the length of the read buffer, and copy 0xCC bytes from it. The length of…

Fix: after 20170502
Fix from $1,950 2021-05-26
Dmg2img HIGH 7.1
CVE-2021-3548

A flaw was found in dmg2img through 20170502. dmg2img did not validate the size of the read buffer during memcpy() inside the main() function. This p…

Fix: after 20170502
Fix from $1,950 2021-05-26
Zephyr CRITICAL 9.8
CVE-2020-13601

Possible read out of bounds in dns read. Zephyr versions >= 1.14.2, >= 2.3.0 contain Out-of-bounds Read (CWE-125). For more information, see https://…

Fix: after 2.3.0
Fix from $2,300 2021-05-25
750 893 Firmware CRITICAL 9.1
CVE-2021-30194

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.

Mitigation only
Fix from $2,300 2021-05-25
750 893 Firmware HIGH 7.5
CVE-2021-30195EPSS 7%

CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.

Mitigation only
Fix from $1,950 2021-05-25
Cranelift Codegen HIGH 8.8
CVE-2021-32629

Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermediate representation into execu…

Fix: 0.73.1+
Fix from $1,950 2021-05-24
Workstation MEDIUM 6.5
CVE-2021-21987

VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado…

Fix: 5.5.2 / 16.1.2+
Fix from $1,600 2021-05-24
Workstation MEDIUM 6.5
CVE-2021-21988

VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado…

Fix: 5.5.2 / 16.1.2+
Fix from $1,600 2021-05-24
Workstation MEDIUM 6.5
CVE-2021-21989

VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado…

Fix: 5.5.2 / 16.1.2+
Fix from $1,600 2021-05-24
Enterprise Linux CRITICAL 9.1
CVE-2018-25009

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25010

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25012

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25013

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Debian Linux CRITICAL 9.1
CVE-2020-36330

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this …

Fix: 1.0.1 / 14.7+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2020-36331

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulne…

Fix: 1.0.1 / 14.7+
Fix from $2,300 2021-05-21
Jboss Core Services HIGH 8.6
CVE-2021-3517EPSS 8%

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be…

Fix: 2.9.11+
Fix from $1,950 2021-05-19
Cncsoft Screeneditor CRITICAL 9.8
CVE-2021-22668

Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds rea…

Fix: after 1.01.28
Fix from $2,300 2021-05-16
Fedora HIGH 7.1
CVE-2020-24119

A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.

Patch available
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.1
CVE-2021-29613

TensorFlow is an end-to-end open source platform for machine learning. Incomplete validation in `tf.raw_ops.CTCLoss` allows an attacker to trigger an…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29606

TensorFlow is an end-to-end open source platform for machine learning. A specially crafted TFLite model could trigger an OOB read on heap in the TFLi…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.1
CVE-2021-29582

TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.Dequantize`, an attacker can trigger …

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29583

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FusedBatchNorm` is vulnerable to a heap buff…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14