Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Barebox CRITICAL 9.1
CVE-2020-13910

Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an incoming network packet is dire…

Fix: after 2020.05.0
Fix from $2,300 2020-06-07
Imagemagick HIGH 7.1
CVE-2020-13902

ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c during TIFF image decoding.

Fix: after 7.0.10-17
Fix from $1,950 2020-06-07
Qemu MEDIUM 5.5
CVE-2020-13791

hw/pci/pci.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access by providing an address near the end of the PCI configuration spa…

Fix: after 5.0.1
Fix from $1,600 2020-06-04
Libjpeg Turbo HIGH 8.1
CVE-2020-13790

libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.

Patch available
Fix from $1,950 2020-06-03
Apq8009 Firmware HIGH 7.1
CVE-2019-14038

Buffer over-read in ADSP parse function due to lack of check for availability of sufficient data payload received in command response in Snapdragon A…

Patch available
Fix from $1,950 2020-06-02
Apq8053 Firmware HIGH 7.1
CVE-2019-14039

Out of bound read in adm call back function due to incorrect boundary check for payload in command response in Snapdragon Auto, Snapdragon Compute, S…

Patch available
Fix from $1,950 2020-06-02
Kamorta Firmware HIGH 7.1
CVE-2019-14042

Out of bound read in in fingerprint application due to requested data assigned to a local buffer without length check in Snapdragon Auto, Snapdragon …

Mitigation only
Fix from $1,950 2020-06-02
Kamorta Firmware HIGH 7.1
CVE-2019-14043

Out of bound read in Fingerprint application due to requested data is being used without length check in Snapdragon Auto, Snapdragon Compute, Snapdra…

Mitigation only
Fix from $1,950 2020-06-02
Apq8009 Firmware HIGH 7.1
CVE-2019-14053

When attempting to create a new XFRM policy, a stack out-of-bounds read will occur if the user provides a template where the mode is set to a value t…

Patch available
Fix from $1,950 2020-06-02
Ar120 S Firmware MEDIUM 6.5
CVE-2020-9071

There is a few bytes out-of-bounds read vulnerability in some Huawei products. The software reads data past the end of the intended buffer when parsi…

Mitigation only
Fix from $1,600 2020-06-01
Debian Linux MEDIUM 5.5
CVE-2020-11089

In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_wr…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 5.4
CVE-2020-11086

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_challenge that reads up to 28 bytes out-of-bound to…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 5.4
CVE-2020-11087

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0.

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 5.4
CVE-2020-11088

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage. This has been fixed in 2.1.0.

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 6.5
CVE-2020-11019

In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 6.5
CVE-2020-11018

In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients could trigger out of bound r…

Fix: after 2.0.0
Fix from $1,600 2020-05-29
Ubuntu Linux MEDIUM 5.5
CVE-2020-13253

sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS …

Fix: after 5.0.1
Fix from $1,600 2020-05-27
Ffjpeg MEDIUM 6.5
CVE-2020-13438

ffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c.

Fix: after 2020-02-24
Fix from $1,600 2020-05-24
Ffjpeg MEDIUM 6.5
CVE-2020-13439

ffjpeg through 2020-02-24 has a heap-based buffer over-read in jfif_decode in jfif.c.

Fix: after 2020-02-24
Fix from $1,600 2020-05-24
Ubuntu Linux HIGH 7.1
CVE-2020-13396

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/l…

Fix: 2.1.1+
Fix from $1,950 2020-05-22
Ubuntu Linux MEDIUM 5.5
CVE-2020-13397

An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/c…

Fix: 2.1.1+
Fix from $1,600 2020-05-22
Debian Linux CRITICAL 9.1
CVE-2020-13112

An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crash…

Fix: 0.6.22+
Fix from $2,300 2020-05-21
Chrome HIGH 8.8
CVE-2020-6458

Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 81.0.4044.122+
Fix from $1,950 2020-05-21
Recursor HIGH 8.8
CVE-2020-10030EPSS 24%

An issue has been found in PowerDNS Recursor 4.1.0 up to and including 4.3.0. It allows an attacker (with enough privileges to change the system's ho…

Fix: after 4.3.0
Fix from $1,950 2020-05-19
Linux Kernel MEDIUM 6.5
CVE-2020-13143

gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibil…

Fix: after 5.6.13
Fix from $1,600 2020-05-18
Ubuntu Linux MEDIUM 6.6
CVE-2020-11521

libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.

Fix: 2.0.0+
Fix from $1,600 2020-05-15
Ubuntu Linux MEDIUM 6.5
CVE-2020-11522

libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read.

Fix: 2.0.0+
Fix from $1,600 2020-05-15
Honor View 20 Firmware HIGH 7.1
CVE-2020-1808

Honor 20;HONOR 20 PRO;Honor Magic2;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;Honor View 20 smartphones with versions earlier than 10.0.0.187(C00E60R…

Fix: 10.0.0.176 / 10.0.0.179+
Fix from $1,950 2020-05-15
Apt MEDIUM 5.5
CVE-2020-3810

Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafte…

Fix: 2.1.2+
Fix from $1,600 2020-05-15
Android MEDIUM 5.5
CVE-2020-0100

In onTransact of IHDCP.cpp, there is a possible out of bounds read due to incorrect error handling. This could lead to local information disclosure o…

Patch available
Fix from $1,600 2020-05-14