Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Libnsbmp HIGH 7.5
CVE-2015-7507

libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1…

No fix yet
Fix from $1,950 2020-02-18
Libnsgif MEDIUM 6.5
CVE-2015-7506

The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and app…

Mitigation only
Fix from $1,600 2020-02-18
Nip6800 Firmware MEDIUM 5.3
CVE-2020-1830

Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600,…

Mitigation only
Fix from $1,600 2020-02-18
Nip6800 Firmware HIGH 7.5
CVE-2020-1828

Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC…

Mitigation only
Fix from $1,950 2020-02-17
Fedora HIGH 7.5
CVE-2019-20454

An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF…

Fix: 8.2.12 / 9.0.6+
Fix from $1,950 2020-02-14
Acrobat Dc HIGH 7.5
CVE-2020-3755

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier …

Fix: after 19.021.20061
Fix from $1,950 2020-02-13
Acrobat Dc HIGH 7.5
CVE-2020-3744EPSS 9%

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier …

Fix: after 19.021.20061
Fix from $1,950 2020-02-13
Acrobat Dc HIGH 7.5
CVE-2020-3747

Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier …

Fix: after 19.021.20061
Fix from $1,950 2020-02-13
Windows 10 MEDIUM 5.5
CVE-2020-0744

An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an att…

Patch available
Fix from $1,600 2020-02-11
Endpoint Protection MEDIUM 5.5
CVE-2020-5826

Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.21…

Mitigation only
Fix from $1,600 2020-02-11
Chrome MEDIUM 6.5
CVE-2020-6405

Out of bounds read in SQLite in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 80.0.3987.87+
Fix from $1,600 2020-02-11
Chrome MEDIUM 6.5
CVE-2020-6395

Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from pr…

Fix: 80.0.3987.87+
Fix from $1,600 2020-02-11
PHP CRITICAL 9.1
CVE-2020-7059EPSS 7%

When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is pos…

Fix: 5.19.0 / 7.2.27+
Fix from $2,300 2020-02-10
PHP CRITICAL 9.1
CVE-2020-7060EPSS 9%

When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it…

Fix: 5.19.0 / 7.2.27+
Fix from $2,300 2020-02-10
Phantompdf HIGH 7.8
CVE-2019-17136EPSS 5%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is r…

Mitigation only
Fix from $1,950 2020-02-08
Apq8009 Firmware CRITICAL 9.1
CVE-2019-14057

Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snapdragon Auto, Snapdragon Compu…

Mitigation only
Fix from $2,300 2020-02-07
Ipq4019 Firmware CRITICAL 9.1
CVE-2019-14063

Out of bound access due to Invalid inputs to dapm mux settings which results into kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon C…

Patch available
Fix from $2,300 2020-02-07
Imagemagick MEDIUM 6.5
CVE-2016-7523

coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

Fix: 6.9.4-0+
Fix from $1,600 2020-02-06
Imagemagick MEDIUM 6.5
CVE-2016-7524

coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

Fix: 6.9.4-0+
Fix from $1,600 2020-02-06
Ubuntu Linux HIGH 7.5
CVE-2020-3123

A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthentica…

Mitigation only
Fix from $1,950 2020-02-05
Minisnmpd CRITICAL 9.1
CVE-2020-6058

An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP reques…

No fix yet
Fix from $2,300 2020-02-04
Nanopb CRITICAL 9.8
CVE-2020-5235

There is a potentially exploitable out of memory condition In Nanopb before 0.4.1, 0.3.9.5, and 0.2.9.4. When nanopb is compiled with PB_ENABLE_MALLO…

Fix: 0.2.9.4 / 0.3.9.5+
Fix from $2,300 2020-02-04
Bromium MEDIUM 6.3
CVE-2019-18567

Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denia…

Fix: after 4.1.7
Fix from $1,600 2020-02-03
Wolfssl CRITICAL 9.8
CVE-2014-2898

wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-o…

Fix: 2.9.0+
Fix from $2,300 2020-01-28
Wolfssl CRITICAL 9.8
CVE-2014-2896

The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact an…

Fix: 2.9.4+
Fix from $2,300 2020-01-28
Wolfssl CRITICAL 9.8
CVE-2014-2897

The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote atta…

Fix: 2.9.4+
Fix from $2,300 2020-01-28
Aspell CRITICAL 9.1
CVE-2019-20433

libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 …

Fix: 0.60.8+
Fix from $2,300 2020-01-27
Lustre HIGH 7.5
CVE-2019-20428

In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds read and panic due to the lack of validation for specific fields of p…

Fix: 2.12.3+
Fix from $1,950 2020-01-27
Lustre HIGH 7.5
CVE-2019-20429

In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds read and panic (via a modified lm_bufcount field) due to the lack of …

Fix: 2.12.3+
Fix from $1,950 2020-01-27
Atidxx64 HIGH 8.6
CVE-2019-5124

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.50005. A specially crafted pixel shader can ca…

Mitigation only
Fix from $1,950 2020-01-25