Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Apq8009 Firmware HIGH 7.1
CVE-2019-10574

Lack of boundary checks for data offsets received from HLOS can lead to out-of-bound read in Snapdragon Auto, Snapdragon Compute, Snapdragon Connecti…

No fix yet
Fix from $1,950 2020-04-16
Apq8009 Firmware CRITICAL 9.1
CVE-2019-10610

Possible buffer over read when trying to process SDP message Video media line with frame-size attribute in video Media line in Snapdragon Auto, Snapd…

Mitigation only
Fix from $2,300 2020-04-16
Apq8009 Firmware CRITICAL 9.1
CVE-2019-10622

Out of bound memory access can happen while parsing ADSP message due to lack of check of size of payload received from userspace in Snapdragon Auto, …

Patch available
Fix from $2,300 2020-04-16
Scada Data Gateway HIGH 7.5
CVE-2020-10613

Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to disclose sensitive information…

Fix: after 4.0.122
Fix from $1,950 2020-04-15
Hmisoft Vu3 Firmware MEDIUM 5.5
CVE-2020-10637

Eaton HMiSoft VU3 (HMIVU3 runtime not impacted), Version 3.00.23 and prior, however, the HMIVU runtimes are not impacted by these issues. A specially…

Fix: after 3.00.23
Fix from $1,600 2020-04-15
Windows 10 MEDIUM 5.5
CVE-2020-0987

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Gra…

Patch available
Fix from $1,600 2020-04-15
Vm Virtualbox MEDIUM 6.0
CVE-2020-2743

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.3…

Fix: 5.2.36 / 6.0.16+
Fix from $1,600 2020-04-15
Vm Virtualbox MEDIUM 6.0
CVE-2020-2741

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.40 / 6.0.20+
Fix from $1,600 2020-04-15
Fedora MEDIUM 5.5
CVE-2020-11758

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11760

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11761

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refi…

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11762

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when h…

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11763

An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Fedora MEDIUM 5.5
CVE-2020-11765

An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Clas…

Fix: 2.4.1 / 7.20+
Fix from $1,600 2020-04-14
Chrome HIGH 8.8
CVE-2020-6455

Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HT…

Fix: 81.0.4044.92+
Fix from $1,950 2020-04-13
Chrome HIGH 8.8
CVE-2020-6447

Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use de…

Fix: 81.0.4044.92+
Fix from $1,950 2020-04-13
Android CRITICAL 9.8
CVE-2018-21072

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos chipsets) software. A kernel driver allows out-of-bounds Re…

Mitigation only
Fix from $2,300 2020-04-08
Android CRITICAL 9.1
CVE-2020-11604

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. There is an Out-of-bounds read in the MLD…

Mitigation only
Fix from $2,300 2020-04-08
Android HIGH 7.5
CVE-2017-18688

An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.0) software. There is an information disclosure (of memory locations o…

Mitigation only
Fix from $1,950 2020-04-07
Android MEDIUM 5.3
CVE-2017-18656

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer over-read in a trustlet. The Samsung ID is SVE-2…

Mitigation only
Fix from $1,600 2020-04-07
Linux Kernel HIGH 7.8
CVE-2020-8835EPSS 6%

In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, le…

Fix: 5.4.29 / 5.5.14+
Fix from $1,950 2020-04-02
Mac Os X CRITICAL 9.8
CVE-2020-3847

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to l…

Fix: 10.15.3+
Fix from $2,300 2020-04-01
Mac Os X HIGH 7.1
CVE-2020-3908

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause …

Fix: 10.15.4+
Fix from $1,950 2020-04-01
Mac Os X HIGH 7.1
CVE-2020-3912

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause …

Fix: 10.15.4+
Fix from $1,950 2020-04-01
Mac Os X HIGH 7.1
CVE-2020-3907

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause …

Fix: 10.15.4+
Fix from $1,950 2020-04-01
PHP MEDIUM 5.4
CVE-2020-7064

In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible f…

Fix: 5.19.0 / 7.2.29+
Fix from $1,600 2020-04-01
Firefox HIGH 8.8
CVE-2020-6806

By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. Th…

Fix: 68.6.0 / 74.0+
Fix from $1,950 2020-03-25
Photoshop 2020 HIGH 7.5
CVE-2020-3777

Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successfu…

Fix: after 21.1
Fix from $1,950 2020-03-25
Acrobat Dc HIGH 7.5
CVE-2020-3806

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and…

Fix: 15.006.30518 / 17.011.30166+
Fix from $1,950 2020-03-25
Acrobat Dc HIGH 7.5
CVE-2020-3804

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and…

Fix: 15.006.30518 / 17.011.30166+
Fix from $1,950 2020-03-25