Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Atidxx64 HIGH 8.6
CVE-2019-5146

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13025.10004. A specially crafted pixel shader can ca…

Mitigation only
Fix from $1,950 2020-01-25
Atidxx64 HIGH 8.6
CVE-2019-5147

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13003.1007. A specially crafted pixel shader can cau…

Mitigation only
Fix from $1,950 2020-01-25
Debian Linux HIGH 7.5
CVE-2019-20387

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of …

Fix: 0.7.6+
Fix from $1,950 2020-01-21
Fedora MEDIUM 6.5
CVE-2019-14907

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or abov…

Fix: 4.9.18 / 4.10.12+
Fix from $1,600 2020-01-21
Apq8009 Firmware CRITICAL 9.8
CVE-2019-10532

Null-pointer dereference issue can occur while calculating string length when source string length is zero in Snapdragon Auto, Snapdragon Connectivit…

Mitigation only
Fix from $2,300 2020-01-21
Apq8009 Firmware CRITICAL 9.1
CVE-2019-10579

Buffer over-read can occur while playing the video clip which is not standard in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdr…

Mitigation only
Fix from $2,300 2020-01-21
Wireshark HIGH 7.5
CVE-2020-7044

In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve …

Fix: 3.2.1+
Fix from $1,950 2020-01-16
Windows 10 MEDIUM 5.5
CVE-2020-0615

An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory…

Patch available
Fix from $1,600 2020-01-14
MariaDB HIGH 7.8
CVE-2015-2325

The compile_branch function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code, cause a denial of service (out-of-bound…

Fix: 5.4.41 / 5.5.26+
Fix from $1,950 2020-01-14
MariaDB MEDIUM 5.5
CVE-2015-2326

The pcre_compile2 function in PCRE before 8.37 allows context-dependent attackers to compile incorrect code and cause a denial of service (out-of-bou…

Fix: 5.4.41 / 5.5.26+
Fix from $1,600 2020-01-14
Nitro Free Pdf Reader MEDIUM 5.5
CVE-2019-19817

The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds…

No fix yet
Fix from $1,600 2020-01-10
Bftpd CRITICAL 9.1
CVE-2020-6162

An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crash…

Mitigation only
Fix from $2,300 2020-01-10
Libming HIGH 8.8
CVE-2020-6628

Ming (aka libming) 0.4.8 has a heap-based buffer over-read in the function decompile_SWITCH() in decompile.c.

No fix yet
Fix from $1,950 2020-01-09
Jhead HIGH 7.1
CVE-2020-6624

jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.

Fix: after 3.04
Fix from $1,950 2020-01-09
Jhead HIGH 7.1
CVE-2020-6625

jhead through 3.04 has a heap-based buffer over-read in Get32s when called from ProcessGpsInfo in gpsinfo.c.

Fix: after 3.04
Fix from $1,950 2020-01-09
Stb Truetype.h HIGH 8.8
CVE-2020-6618

stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.

Fix: after 1.22
Fix from $1,950 2020-01-08
Stb Truetype.h HIGH 8.8
CVE-2020-6620

stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.

Fix: after 1.22
Fix from $1,950 2020-01-08
Stb Truetype.h HIGH 8.8
CVE-2020-6621

stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.

Fix: after 1.22
Fix from $1,950 2020-01-08
Stb Truetype.h HIGH 8.8
CVE-2020-6622

stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.

Fix: after 1.22
Fix from $1,950 2020-01-08
Libredwg HIGH 8.8
CVE-2020-6609

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.

Patch available
Fix from $1,950 2020-01-08
Libredwg HIGH 8.1
CVE-2020-6612

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.

No fix yet
Fix from $1,950 2020-01-08
Libredwg HIGH 8.1
CVE-2020-6613

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.

No fix yet
Fix from $1,950 2020-01-08
Libredwg HIGH 8.1
CVE-2020-6614

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.

No fix yet
Fix from $1,950 2020-01-08
Debian Linux CRITICAL 9.1
CVE-2019-20367

nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).

Fix: 0.10.0+
Fix from $2,300 2020-01-08
Enterprise Linux CRITICAL 9.8
CVE-2019-14906

A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL pack…

Fix: after 2.0.9
Fix from $2,300 2020-01-07
Netwide Assembler HIGH 7.1
CVE-2019-20352

In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand_one_smac…

No fix yet
Fix from $1,950 2020-01-06
Pillow HIGH 7.1
CVE-2020-5313

libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.

Fix: 6.2.2+
Fix from $1,950 2020-01-03
Ngiflib HIGH 8.8
CVE-2019-20219

ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c.

No fix yet
Fix from $1,950 2020-01-02
Ezxml MEDIUM 6.5
CVE-2019-20199

An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, performs incorrect memory handling…

Fix: after 0.8.6
Fix from $1,600 2019-12-31
Ezxml MEDIUM 6.5
CVE-2019-20200

An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, performs incorrect memory handling…

Fix: after 0.8.6
Fix from $1,600 2019-12-31