Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Prelude MEDIUM 6.5
CVE-2020-9679

Adobe Prelude versions 9.0 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution.

Fix: after 9.0
Fix from $1,600 2020-07-22
Photoshop HIGH 8.8
CVE-2020-9683

Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitr…

Fix: after 21.2
Fix from $1,950 2020-07-22
Photoshop MEDIUM 6.5
CVE-2020-9686

Adobe Photoshop versions Photoshop CC 2019, and Photoshop 2020 have an out-of-bounds read vulnerability. Successful exploitation could lead to arbitr…

Fix: after 21.2
Fix from $1,600 2020-07-22
Lua HIGH 8.8
CVE-2020-15888

Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer…

Patch available
Fix from $1,950 2020-07-21
Lua CRITICAL 9.8
CVE-2020-15889

Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.

Patch available
Fix from $2,300 2020-07-21
Debian Linux HIGH 7.5
CVE-2020-15890

LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.

Fix: after 2.0.5
Fix from $1,950 2020-07-21
Media Encoder MEDIUM 5.5
CVE-2020-9649

Adobe Media Encoder versions 14.2 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 14.2
Fix from $1,600 2020-07-17
Libredwg HIGH 8.1
CVE-2019-20910

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a di…

Fix: after 0.9.3
Fix from $1,950 2020-07-16
Libredwg HIGH 8.1
CVE-2019-20913

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity…

Fix: after 0.9.3
Fix from $1,950 2020-07-16
Libredwg HIGH 8.1
CVE-2019-20915

An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c.

Fix: after 0.9.3
Fix from $1,950 2020-07-16
Antivirus\+ 2020 HIGH 7.5
CVE-2020-15603

An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attack…

Fix: after 16.0.1302
Fix from $1,950 2020-07-15
Vm Virtualbox MEDIUM 5.3
CVE-2020-14698

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.44 / 6.0.24+
Fix from $1,600 2020-07-15
Vm Virtualbox MEDIUM 5.3
CVE-2020-14700

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.44 / 6.0.24+
Fix from $1,600 2020-07-15
Vm Virtualbox MEDIUM 5.3
CVE-2020-14694

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.44 / 6.0.24+
Fix from $1,600 2020-07-15
Vm Virtualbox MEDIUM 5.3
CVE-2020-14695

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.44 / 6.0.24+
Fix from $1,600 2020-07-15
Vm Virtualbox HIGH 7.5
CVE-2020-14676

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.44 / 6.0.24+
Fix from $1,950 2020-07-15
Tor HIGH 7.5
CVE-2020-15572

Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozill…

Fix: 0.3.5.11 / 0.4.2.8+
Fix from $1,950 2020-07-15
365 Apps MEDIUM 5.5
CVE-2020-1342EPSS 6%

An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could…

Patch available
Fix from $1,600 2020-07-14
Sicam Mmu Firmware HIGH 7.5
CVE-2020-10037

A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). By performing a fl…

Fix: 2.05 / 2.18+
Fix from $1,950 2020-07-14
Openstack MEDIUM 6.5
CVE-2020-10756

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echorep…

Fix: 4.3.1+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12425

Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information d…

Fix: 78.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12407

Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible scre…

Fix: 77.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12418

Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerabi…

Fix: 68.10 / 68.10.0+
Fix from $1,600 2020-07-09
Pc Worx HIGH 7.8
CVE-2020-12498

mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. M…

Fix: 1.87+
Fix from $1,950 2020-07-01
Ndpi CRITICAL 9.1
CVE-2020-15471

In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.

Fix: after 3.2
Fix from $2,300 2020-07-01
Debian Linux CRITICAL 9.1
CVE-2020-15472

In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated …

Fix: after 3.2
Fix from $2,300 2020-07-01
Ndpi CRITICAL 9.1
CVE-2020-15473

In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.

Fix: after 3.2
Fix from $2,300 2020-07-01
Debian Linux HIGH 7.5
CVE-2020-15476

In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c.

Fix: after 3.2
Fix from $1,950 2020-07-01
Virtual Gpu Manager HIGH 7.8
CVE-2020-5971

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software reads from a buffer by using buffer access mechanisms s…

Fix: after 10.2
Fix from $1,950 2020-06-30
Daoffice HIGH 7.8
CVE-2020-7816

A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker to cause a…

Fix: 8.995+
Fix from $1,950 2020-06-30