Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Asylo MEDIUM 5.5
CVE-2020-8939

An out of bounds read on the enc_untrusted_inet_ntop function allows an attack to extend the result size that is used by memcpy() to read memory from…

Fix: after 0.6.0
Fix from $1,600 2020-12-15
Asylo MEDIUM 5.5
CVE-2020-8940

An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvmsg using an at…

Fix: after 0.6.0
Fix from $1,600 2020-12-15
Asylo MEDIUM 5.5
CVE-2020-8941

An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_inet_pton using an …

Fix: after 0.6.0
Fix from $1,600 2020-12-15
Asylo MEDIUM 5.5
CVE-2020-8942

An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_read whose return s…

Fix: after 0.6.0
Fix from $1,600 2020-12-15
Asylo MEDIUM 5.5
CVE-2020-8943

An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvfrom whose retu…

Fix: after 0.6.0
Fix from $1,600 2020-12-15
Android HIGH 7.5
CVE-2020-0463

In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote inf…

Patch available
Fix from $1,950 2020-12-14
Picotcp HIGH 7.5
CVE-2020-24339

An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The DNS domain name record decompression functionality in pico_dns_decompress_name()…

Fix: after 1.7.0
Fix from $1,950 2020-12-11
Picotcp HIGH 7.5
CVE-2020-24340

An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The code that processes DNS responses in pico_mdns_handle_data_as_answers_generic() …

Fix: after 1.7.0
Fix from $1,950 2020-12-11
Picotcp CRITICAL 9.1
CVE-2020-24341

An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The TCP input data processing function in pico_tcp.c does not validate the length of…

Fix: after 1.7.0
Fix from $2,300 2020-12-11
Fnet CRITICAL 9.1
CVE-2020-24383

An issue was discovered in FNET through 4.6.4. The code for processing resource records in mDNS queries doesn't check for proper '\0' termination of …

Fix: after 4.6.4
Fix from $2,300 2020-12-11
Nut\/os CRITICAL 9.8
CVE-2020-25107EPSS 52%

An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. There is no check on whether a domain name has '\0' termination. This ma…

Fix: after 5.1
Fix from $2,300 2020-12-11
Nut\/os CRITICAL 9.8
CVE-2020-25109EPSS 52%

An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The number of DNS queries/responses (set in a DNS header) is not checked…

Fix: after 5.1
Fix from $2,300 2020-12-11
Nut\/os CRITICAL 9.8
CVE-2020-25110EPSS 52%

An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS query/response is not checked,…

Fix: after 5.1
Fix from $2,300 2020-12-11
Picotcp CRITICAL 9.1
CVE-2020-17441EPSS 7%

An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 headers does not validate whether the IPv6 payload length field is equal t…

Fix: 3.7.0+
Fix from $2,300 2020-12-11
Picotcp HIGH 7.5
CVE-2020-17445

An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 destination options does not check for a valid length of the destination o…

Fix: after 1.7.0
Fix from $1,950 2020-12-11
Fnet CRITICAL 9.1
CVE-2020-17467

An issue was discovered in FNET through 4.6.4. The code for processing the hostname from an LLMNR request doesn't check for '\0' termination. Therefo…

Fix: after 4.6.4
Fix from $2,300 2020-12-11
Fnet HIGH 7.5
CVE-2020-17468

An issue was discovered in FNET through 4.6.4. The code for processing the hop-by-hop header (in the IPv6 extension headers) doesn't check for a vali…

Fix: after 4.6.4
Fix from $1,950 2020-12-11
Uip HIGH 8.2
CVE-2020-24334

The code that processes DNS responses in uIP through 1.0, as used in Contiki and Contiki-NG, does not check whether the number of responses specified…

Fix: after 1.0
Fix from $1,950 2020-12-11
Uip HIGH 7.5
CVE-2020-13987

An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the che…

Fix: 2.3.0 / 2.4.7+
Fix from $1,950 2020-12-11
Wireshark MEDIUM 5.3
CVE-2020-26421

Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection…

Fix: after 3.2.8
Fix from $1,600 2020-12-11
Tensorflow HIGH 7.8
CVE-2020-26267

In affected versions of TensorFlow the tf.raw_ops.DataFormatVecPermute API does not validate the src_format and dst_format attributes. The code assum…

Fix: 1.15.5 / 2.0.4+
Fix from $1,950 2020-12-10
Tensorflow HIGH 7.5
CVE-2020-26269

In TensorFlow release candidate versions 2.4.0rc*, the general implementation for matching filesystem paths to globbing pattern is vulnerable to an a…

Patch available
Fix from $1,950 2020-12-10
Binutils MEDIUM 5.5
CVE-2020-16591

A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read in process_symbol_table, as …

Patch available
Fix from $1,600 2020-12-09
Jerryscript CRITICAL 9.1
CVE-2020-29657

In JerryScript 2.3.0, there is an out-of-bounds read in main_print_unhandled_exception in the main-utils.c file.

Mitigation only
Fix from $2,300 2020-12-09
Ipados HIGH 7.8
CVE-2020-27909

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processi…

Fix: 7.1 / 11.0.1+
Fix from $1,950 2020-12-08
Ipados HIGH 7.8
CVE-2020-27910

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2,…

Fix: 7.1 / 11.0.1+
Fix from $1,950 2020-12-08
Debian Linux MEDIUM 5.5
CVE-2020-25665

The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() because it needs to be offset by 2…

Fix: 6.9.10-68 / 7.0.8-68+
Fix from $1,600 2020-12-08
Ipados HIGH 7.8
CVE-2020-9965

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and…

Fix: 7.0 / 11.0.1+
Fix from $1,950 2020-12-08
Ipados HIGH 7.8
CVE-2020-9966

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and…

Fix: 7.0 / 11.0.1+
Fix from $1,950 2020-12-08
Ipados MEDIUM 5.5
CVE-2020-9943

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and …

Fix: 7.0 / 10.14.6+
Fix from $1,600 2020-12-08