Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux MEDIUM 5.5
CVE-2019-15142

In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup …

Patch available
Fix from $1,600 2019-08-18
Linux Kernel MEDIUM 6.7
CVE-2019-15090

An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-…

Fix: 5.1.12+
Fix from $1,600 2019-08-16
Delta Industrial Automation Dopsoft HIGH 7.8
CVE-2019-13513

In Delta Industrial Automation DOPSoft, Version 4.00.06.15 and prior, processing a specially crafted project file may trigger multiple out-of-bounds …

Fix: after 4.00.06.15
Fix from $1,950 2019-08-15
Debian Linux HIGH 7.1
CVE-2019-13222

An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service o…

Fix: after 2019-03-04
Fix from $1,950 2019-08-15
Office MEDIUM 5.5
CVE-2019-1153

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who su…

Patch available
Fix from $1,600 2019-08-14
Office MEDIUM 5.5
CVE-2019-1148

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who su…

Patch available
Fix from $1,600 2019-08-14
Stb CRITICAL 9.1
CVE-2019-15058

stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or Denial of Servi…

No fix yet
Fix from $2,300 2019-08-14
Bento4 HIGH 8.8
CVE-2019-15047

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBits at Core/Ap4Utils.cpp.

No fix yet
Fix from $1,950 2019-08-14
Bento4 HIGH 8.8
CVE-2019-15049

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp.

No fix yet
Fix from $1,950 2019-08-14
Bento4 HIGH 8.8
CVE-2019-15050

An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp.

No fix yet
Fix from $1,950 2019-08-14
Mupdf HIGH 7.1
CVE-2019-14975

Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a miss…

Fix: 1.16.0+
Fix from $1,950 2019-08-14
PHP HIGH 7.1
CVE-2019-11041

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x belo…

Fix: 5.19.0 / 7.1.31+
Fix from $1,950 2019-08-09
PHP HIGH 7.1
CVE-2019-11042

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x belo…

Fix: 5.19.0 / 7.1.31+
Fix from $1,950 2019-08-09
Cpanel MEDIUM 6.3
CVE-2017-18446

cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
The Sleuth Kit CRITICAL 9.8
CVE-2019-14531

An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol data in fs…

No fix yet
Fix from $2,300 2019-08-02
Debian Linux HIGH 7.5
CVE-2019-14513

Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation be…

Fix: 2.76+
Fix from $1,950 2019-08-01
Opencv HIGH 8.2
CVE-2019-14491

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::predictOrdered<cv::HaarEvalua…

Fix: 3.4.7 / 4.1.1+
Fix from $1,950 2019-08-01
Opencv HIGH 7.5
CVE-2019-14492

An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read/write in the function HaarEvaluator::OptFeature::…

Fix: 3.4.7 / 4.1.1+
Fix from $1,950 2019-08-01
Fedora CRITICAL 9.1
CVE-2019-14463

An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS c…

Fix: 3.0.7 / 3.1.5+
Fix from $2,300 2019-07-31
Fedora CRITICAL 9.1
CVE-2019-14462

An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case,…

Fix: 3.0.7 / 3.1.5+
Fix from $2,300 2019-07-31
Endpoint Protection HIGH 7.8
CVE-2019-12750

Symantec Endpoint Protection, prior to 14.2 RU1 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition, prior to 12.1 RU6 MP10c (12.…

No fix yet
Fix from $1,950 2019-07-31
U Boot CRITICAL 9.1
CVE-2019-14197

An issue was discovered in Das U-Boot through 2019.07. There is a read of out-of-bounds data at nfs_read_reply.

Fix: after 2019.07
Fix from $2,300 2019-07-31
Debian Linux MEDIUM 6.5
CVE-2019-14380

libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files.

Fix: 0.4.5+
Fix from $1,600 2019-07-30
PostgreSQL MEDIUM 6.5
CVE-2019-10129

A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbi…

Fix: 11.3+
Fix from $1,600 2019-07-30
Freetype CRITICAL 9.8
CVE-2015-9290

In FreeType before 2.6.1, a buffer over-read occurs in type1/t1parse.c on function T1_Get_Private_Dict where there is no check that the new values of…

Fix: 2.6.1+
Fix from $2,300 2019-07-30
Debian Linux MEDIUM 6.5
CVE-2019-14370

In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service.

No fix yet
Fix from $1,600 2019-07-28
Flif HIGH 7.8
CVE-2019-14373

An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can trigger a heap-based buffer …

No fix yet
Fix from $1,950 2019-07-28
Exiv2 HIGH 7.8
CVE-2019-14368

Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp.

No fix yet
Fix from $1,950 2019-07-28
Debian Linux MEDIUM 6.5
CVE-2019-14369

Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer over-read) via a …

No fix yet
Fix from $1,600 2019-07-28
Linux Kernel MEDIUM 5.5
CVE-2015-9289

In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size …

Fix: 4.1.4+
Fix from $1,600 2019-07-27