Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Imagemagick MEDIUM 5.5
CVE-2020-10251

In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c. It can be triggered via an i…

Patch available
Fix from $1,600 2020-03-10
The Sleuth Kit CRITICAL 9.1
CVE-2020-10233

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.

Fix: after 4.8.0
Fix from $2,300 2020-03-09
Debian Linux MEDIUM 6.5
CVE-2019-20503

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

Fix: 0.9.4.0+
Fix from $1,600 2020-03-06
Sm8150 Firmware HIGH 7.8
CVE-2019-14048

Possible out of bound memory access while playing a crafted clip in media player in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Sna…

Mitigation only
Fix from $1,950 2020-03-05
Apq8098 Firmware HIGH 7.1
CVE-2019-14081

Buffer Over-read when WLAN module gets a WMI message for SAR limits with invalid number of limits to be enforced in Snapdragon Compute, Snapdragon Co…

Mitigation only
Fix from $1,950 2020-03-05
Ipq8074 Firmware CRITICAL 9.1
CVE-2019-14082

Potential buffer over-read due to lack of bound check of memory offset passed in WLAN firmware in Snapdragon Compute, Snapdragon Consumer Electronics…

Mitigation only
Fix from $2,300 2020-03-05
Mdm9206 Firmware CRITICAL 9.1
CVE-2019-10550

Buffer Over-read when UE is trying to process the message received form the network without zero termination in Snapdragon Auto, Snapdragon Compute, …

Mitigation only
Fix from $2,300 2020-03-05
Apq8009 Firmware CRITICAL 9.1
CVE-2019-10552

Multiple Buffer Over-read issue can happen due to improper length checks while decoding Service Reject/RAU Reject/PTMSI Realloc cmd in Snapdragon Aut…

No fix yet
Fix from $2,300 2020-03-05
Apq8009 Firmware CRITICAL 9.1
CVE-2019-10553

Multiple Read overflows due to improper length checks while decoding authentication in Cs domain/RAU Reject and TC cmd in Snapdragon Auto, Snapdragon…

No fix yet
Fix from $2,300 2020-03-05
Apq8009 Firmware CRITICAL 9.1
CVE-2019-10554

Multiple Read overflows issue due to improper length check while decoding Identity Request in CSdomain/Authentication Reject in CS domain/ PRAU accep…

No fix yet
Fix from $2,300 2020-03-05
Apq8009 Firmware CRITICAL 9.1
CVE-2019-10577

Improper input validation while processing SIP URI received from the network will lead to buffer over-read and then to denial of service in Snapdrago…

Mitigation only
Fix from $2,300 2020-03-05
Hhvm HIGH 7.5
CVE-2020-1893

Insufficient boundary checks when decoding JSON in TryParse reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.45.0, 4…

Fix: 4.8.7+
Fix from $1,950 2020-03-03
Hhvm HIGH 7.5
CVE-2020-1888

Insufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.…

Fix: 4.8.7+
Fix from $1,950 2020-03-03
Hhvm HIGH 8.1
CVE-2020-1892

Insufficient boundary checks when decoding JSON in JSON_parser allows read access to out of bounds memory, potentially leading to information leak an…

Fix: 4.8.7+
Fix from $1,950 2020-03-03
Nip6800 Firmware HIGH 7.5
CVE-2020-1873

NIP6800;Secospace USG6600;USG9500 products with versions of V500R001C30; V500R001C60SPC500; V500R005C00SPC100 have an out-of-bounds read vulnerabilit…

Mitigation only
Fix from $1,950 2020-02-28
Wireshark HIGH 7.5
CVE-2020-9428

In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c b…

Fix: after 3.2.1
Fix from $1,950 2020-02-27
Ipados HIGH 7.8
CVE-2020-3870

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS…

Fix: 6.1.2 / 10.15.3+
Fix from $1,950 2020-02-27
Ipados MEDIUM 5.5
CVE-2020-3875

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS …

Fix: 6.1.2 / 10.15.3+
Fix from $1,600 2020-02-27
Mac Os X HIGH 7.5
CVE-2020-3877

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3, watchOS 6.1.2. A remote attacker m…

Fix: 6.1.2 / 10.15.3+
Fix from $1,950 2020-02-27
Icloud HIGH 7.8
CVE-2020-3878EPSS 9%

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.…

Fix: 6.2.5 / 7.19+
Fix from $1,950 2020-02-27
PHP CRITICAL 9.1
CVE-2020-7061

In PHP versions 7.3.x below 7.3.15 and 7.4.x below 7.4.3, while extracting PHAR files on Windows using phar extension, certain content inside PHAR fi…

Fix: 5.19.0+
Fix from $2,300 2020-02-27
Ipados HIGH 7.8
CVE-2020-3829

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS …

Fix: 6.1.2 / 10.15.3+
Fix from $1,950 2020-02-27
Icloud HIGH 7.8
CVE-2020-3826

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS…

Fix: 6.1.2 / 10.15.3+
Fix from $1,950 2020-02-27
Libgd HIGH 8.1
CVE-2017-6363

In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my…

Fix: after 2.2.5
Fix from $1,950 2020-02-27
Ubuntu Linux CRITICAL 9.8
CVE-2020-8794EPSS 89%

OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this…

Fix: 6.6.4+
Fix from $2,300 2020-02-25
Linux Kernel HIGH 7.1
CVE-2020-9383

An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read becaus…

Fix: after 5.5.6
Fix from $1,950 2020-02-25
Awk 3131a Firmware HIGH 7.5
CVE-2019-5148

An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted…

No fix yet
Fix from $1,950 2020-02-25
Fedora HIGH 7.5
CVE-2020-9365EPSS 7%

An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.

Patch available
Fix from $1,950 2020-02-24
Proftpd HIGH 7.5
CVE-2020-9272

ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.

Fix: 1.3.6c / 3.0+
Fix from $1,950 2020-02-20
Fedora CRITICAL 9.8
CVE-2020-6061EPSS 5%

An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST …

No fix yet
Fix from $2,300 2020-02-19