Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Apq8009 Firmware CRITICAL 9.8
CVE-2019-2303

SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consum…

Mitigation only
Fix from $2,300 2019-11-21
Apq8017 Firmware MEDIUM 5.5
CVE-2019-2318

Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snapdragon Connectivity, Snapdrag…

Mitigation only
Fix from $1,600 2019-11-21
Apq8009 Firmware CRITICAL 9.8
CVE-2019-2268

Possible OOB read issue in P2P action frames while handling WLAN management frame in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, S…

Patch available
Fix from $2,300 2019-11-21
Apq8009 Firmware CRITICAL 9.8
CVE-2019-2271

Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values in Snapdragon Auto, Snapdragon…

Mitigation only
Fix from $2,300 2019-11-21
Apq8053 Firmware HIGH 7.8
CVE-2019-10563

Buffer over-read can occur in fast message handler due to improper input validation while processing a message from firmware in Snapdragon Auto, Snap…

Patch available
Fix from $1,950 2019-11-21
Debian Linux CRITICAL 9.8
CVE-2019-19012EPSS 11%

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offse…

Fix: after 6.9.3
Fix from $2,300 2019-11-17
Jhead MEDIUM 5.5
CVE-2019-19035

jhead 3.03 is affected by: heap-based buffer over-read. The impact is: Denial of service. The component is: ReadJpegSections and process_SOFn in jpgf…

No fix yet
Fix from $1,600 2019-11-17
Graphics Driver MEDIUM 5.5
CVE-2019-14574

Out of bounds read in a subsystem for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable d…

Fix: 26.20.100.7209+
Fix from $1,600 2019-11-14
Baseboard Management Controller Firmware HIGH 7.8
CVE-2019-11181

Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable escalation of privileg…

Fix: 2.18+
Fix from $1,950 2019-11-14
Baseboard Management Controller Firmware MEDIUM 5.3
CVE-2019-11172

Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure…

Fix: 2.18+
Fix from $1,600 2019-11-14
Android MEDIUM 5.5
CVE-2019-2209

In BTA_DmPinReply of bta_dm_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information dis…

Mitigation only
Fix from $1,600 2019-11-13
Android MEDIUM 5.5
CVE-2019-2212

In poisson_distribution of random, there is an out of bounds read. This could lead to local information disclosure with no additional execution privi…

Mitigation only
Fix from $1,600 2019-11-13
Android CRITICAL 9.8
CVE-2019-2204

In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in AST traversal. This could lead to remote code exe…

Mitigation only
Fix from $2,300 2019-11-13
Android HIGH 7.5
CVE-2019-2208

In PromiseBuiltinsAssembler::NewPromiseCapability of builtins-promise.cc, there is a possible out of bounds read in v8 JIT code due to a bug in code …

Mitigation only
Fix from $1,950 2019-11-13
Manageone HIGH 7.5
CVE-2019-5289

Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific pa…

Mitigation only
Fix from $1,950 2019-11-13
Ar120 S Firmware HIGH 7.5
CVE-2019-5294

There is an out of bound read vulnerability in some Huawei products. A remote, unauthenticated attacker may send a corrupt or crafted message to the …

Mitigation only
Fix from $1,950 2019-11-13
Windows 7 MEDIUM 6.5
CVE-2019-1432EPSS 5%

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…

Patch available
Fix from $1,600 2019-11-12
Windows 10 MEDIUM 6.5
CVE-2019-1411

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclos…

Patch available
Fix from $1,600 2019-11-12
Windows 7 MEDIUM 5.5
CVE-2019-1412

An information disclosure vulnerability exists in Windows Adobe Type Manager Font Driver (ATMFD.dll) when it fails to properly handle objects in memo…

Patch available
Fix from $1,600 2019-11-12
Fedora MEDIUM 5.5
CVE-2019-18849

In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat ap…

Fix: 1.4.18+
Fix from $1,600 2019-11-11
Linux Kernel CRITICAL 9.1
CVE-2014-3180

In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_s…

Fix: 3.17+
Fix from $2,300 2019-11-06
Ipq8074 Firmware CRITICAL 9.8
CVE-2019-2249

Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Co…

Mitigation only
Fix from $2,300 2019-11-06
Mdm9150 Firmware CRITICAL 9.8
CVE-2019-2283

Improper validation of read and write index of tx and rx fifo`s before calculating pointer can lead to out-of-bound access in Snapdragon Auto, Snapdr…

Patch available
Fix from $2,300 2019-11-06
Mdm9150 Firmware CRITICAL 9.8
CVE-2019-10505

Out of bound access while processing a non-standard IE measurement request with length crossing past the size of frame in Snapdragon Auto, Snapdragon…

Patch available
Fix from $2,300 2019-11-06
Mdm9150 Firmware CRITICAL 9.8
CVE-2019-10542

Buffer over-read may occur when downloading a corrupted firmware file that has chunk length in header which doesn`t match the contents in Snapdragon …

Patch available
Fix from $2,300 2019-11-06
Libsass MEDIUM 6.5
CVE-2019-18798

LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.

Fix: 3.6.3+
Fix from $1,600 2019-11-06
Clamav HIGH 7.5
CVE-2019-1789

ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read condition may occur when scan…

Fix: 0.101.2+
Fix from $1,950 2019-11-05
Config\+ HIGH 7.8
CVE-2019-16675

An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Con…

Fix: after 1.86
Fix from $1,950 2019-10-31
Rdesktop HIGH 7.5
CVE-2019-15682

RDesktop version 1.8.4 contains multiple out-of-bound access read vulnerabilities in its code, which results in a denial of service (DoS) condition. …

Mitigation only
Fix from $1,950 2019-10-30
Thrift HIGH 7.5
CVE-2019-0210EPSS 7%

In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.

Fix: after 0.12.0
Fix from $1,950 2019-10-29