Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Apq8009 Firmware CRITICAL 9.8
CVE-2019-10559

Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then memory corruption in Snapdragon …

Mitigation only
Fix from $2,300 2019-12-12
Apq8009 Firmware HIGH 7.5
CVE-2019-2310

Out of bound read would occur while trying to read action category and action ID without validating the action length of the Rx Frame body in Snapdra…

Patch available
Fix from $1,950 2019-12-12
Leadtools HIGH 7.5
CVE-2019-5090

An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15…

Mitigation only
Fix from $1,950 2019-12-12
Windows 10 MEDIUM 6.5
CVE-2019-1465EPSS 6%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor…

Patch available
Fix from $1,600 2019-12-10
Windows 10 MEDIUM 6.5
CVE-2019-1466EPSS 6%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Infor…

Patch available
Fix from $1,600 2019-12-10
Chrome MEDIUM 6.5
CVE-2019-13753

Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 79.0.3945.79+
Fix from $1,600 2019-12-10
Chrome MEDIUM 6.5
CVE-2019-13752

Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 79.0.3945.79+
Fix from $1,600 2019-12-10
Fedora HIGH 7.8
CVE-2019-19648

In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO…

No fix yet
Fix from $1,950 2019-12-09
Linux Kernel HIGH 7.8
CVE-2019-19449

In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f…

No fix yet
Fix from $1,950 2019-12-08
Android MEDIUM 5.5
CVE-2019-2226

In device_class_to_int of device_class.cc, there is a possible out of bounds read due to improper casting. This could lead to local information discl…

Mitigation only
Fix from $1,600 2019-12-06
Android MEDIUM 6.5
CVE-2019-2227

In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting. This could lead to remote information disclosure over Blue…

Patch available
Fix from $1,600 2019-12-06
Android MEDIUM 5.5
CVE-2019-2228

In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to local information disclosure in…

Mitigation only
Fix from $1,600 2019-12-06
Enterprise Linux MEDIUM 6.5
CVE-2019-19624

An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_s…

Fix: 4.1.1+
Fix from $1,600 2019-12-06
Workstation HIGH 8.6
CVE-2019-5098

An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A specially crafted pixel shader can ca…

No fix yet
Fix from $1,950 2019-12-05
Folly CRITICAL 9.8
CVE-2019-11934

Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly prior to v2019.11.04.00.

Fix: 2019.11.04.00+
Fix from $2,300 2019-12-04
Hhvm CRITICAL 9.8
CVE-2019-11935

Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prio…

Fix: 3.30.12+
Fix from $2,300 2019-12-04
Debian Linux HIGH 7.5
CVE-2012-4428EPSS 10%

openslp: SLPIntersectStringList()' Function has a DoS vulnerability

Mitigation only
Fix from $1,950 2019-12-02
Debian Linux MEDIUM 5.5
CVE-2019-19479

An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsin…

Fix: after 0.19.0
Fix from $1,600 2019-12-01
P30 Firmware MEDIUM 5.5
CVE-2019-5224

P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds read vulnerability. The system does not properly …

Mitigation only
Fix from $1,600 2019-11-29
Mongoose CRITICAL 9.8
CVE-2019-19307EPSS 42%

An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infinite loop), or possibly cause …

No fix yet
Fix from $2,300 2019-11-26
Typed Ast HIGH 7.5
CVE-2019-19274

typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Pytho…

Patch available
Fix from $1,950 2019-11-26
Typed Ast HIGH 7.5
CVE-2019-19275

typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python sou…

Patch available
Fix from $1,950 2019-11-26
Linux Kernel HIGH 7.8
CVE-2019-19252

vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through 5.3.13 does not prevent write access to vcsu devices, aka CID-0c9acb1af77a.

Fix: after 5.3.13
Fix from $1,950 2019-11-25
PHP HIGH 7.5
CVE-2019-19246

Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

Fix: 7.3.10+
Fix from $1,950 2019-11-25
Chrome HIGH 8.1
CVE-2019-5881

Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to obtain potentially sensitive information from p…

Fix: 77.0.3865.75+
Fix from $1,950 2019-11-25
Chrome MEDIUM 6.5
CVE-2019-5867

Out of bounds read in JavaScript in Google Chrome prior to 76.0.3809.100 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 76.0.3809.100+
Fix from $1,600 2019-11-25
Chrome HIGH 8.1
CVE-2019-5849

Out of bounds read in Skia in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to obtain potentially sensitive information from process …

Fix: 75.0.3770.80+
Fix from $1,950 2019-11-25
Debian Linux MEDIUM 5.5
CVE-2019-19221

In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. Fo…

Patch available
Fix from $1,600 2019-11-21
Fedora HIGH 7.5
CVE-2019-19203

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced wit…

Fix: 6.9.4+
Fix from $1,950 2019-11-21
Debian Linux HIGH 7.5
CVE-2019-19204EPSS 7%

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in re…

Fix: 6.9.4+
Fix from $1,950 2019-11-21