Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Mpc Hc HIGH 7.8
CVE-2019-17260

MPC-HC through 1.7.13 allows a Read Access Violation on a Block Data Move starting at mpc_hc!memcpy+0x000000000000004e.

Fix: after 1.7.13
Fix from $1,950 2019-10-08
Amazon Web Services Freertos HIGH 7.5
CVE-2019-13120

Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory …

Fix: after 1.4.8
Fix from $1,950 2019-10-07
Ubuntu Linux CRITICAL 9.8
CVE-2019-17266

libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properl…

Fix: 2.66.4+
Fix from $2,300 2019-10-06
Reader HIGH 7.8
CVE-2019-13331

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is requi…

Fix: after 9.6.0.25114
Fix from $1,950 2019-10-03
Foxit Studio Photo HIGH 7.8
CVE-2019-13324

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.909. User interaction is r…

Fix: after 3.6.6.911
Fix from $1,950 2019-10-03
Foxit Studio Photo HIGH 7.8
CVE-2019-13325

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.909. User interaction is r…

Fix: after 3.6.6.911
Fix from $1,950 2019-10-03
Reader HIGH 7.8
CVE-2019-13326

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.20723. User interaction is requi…

Fix: after 9.6.0.25114
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14470

The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14880EPSS 5%

The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().

Fix: after 15.0.1
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14881

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-14882

The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16227EPSS 7%

The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16228

The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-16229EPSS 7%

The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16230

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16451

The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14461

The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-14462

The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-14463

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-20…

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14464

The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-14465

The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14466

The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14467

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14468

The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().

Fix: after 15.0.1
Fix from $1,950 2019-10-03
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2018-14469EPSS 5%

The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Bsafe Crypto C HIGH 7.5
CVE-2019-3728

RSA BSAFE Crypto-C Micro Edition versions from 4.0.0.0 before 4.0.5.4 and from 4.1.0 before 4.1.4, RSA BSAFE Micro Edition Suite versions from 4.0.0 …

Fix: 4.0.5.4 / 4.0.13+
Fix from $1,950 2019-09-30
Mdm9150 Firmware HIGH 7.8
CVE-2019-10507

Lack of check of extscan change results received from firmware can lead to an out of buffer read in Snapdragon Auto, Snapdragon Consumer Electronics …

Patch available
Fix from $1,950 2019-09-30
Rsyslog CRITICAL 9.8
CVE-2019-17040

contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.

Patch available
Fix from $2,300 2019-09-30
Android MEDIUM 5.5
CVE-2019-9435

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additiona…

Mitigation only
Fix from $1,600 2019-09-27
Android HIGH 7.5
CVE-2019-9462

In Bluetooth, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional…

Mitigation only
Fix from $1,950 2019-09-27