Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Njs MEDIUM 6.5
CVE-2019-13617

njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error handling, as demonstrated by an…

Fix: after 0.3.3
Fix from $1,600 2019-07-16
Gpac HIGH 7.5
CVE-2019-13618

In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in gf_m2ts_sync in media_tools/…

Fix: 0.8.0+
Fix from $1,950 2019-07-16
Op Tee CRITICAL 9.8
CVE-2019-1010295

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The compon…

Fix: after 3.3.0
Fix from $2,300 2019-07-15
Sound Exchange MEDIUM 5.5
CVE-2019-1010004

SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function…

Fix: after 14.4.2
Fix from $1,600 2019-07-15
Debian Linux MEDIUM 5.9
CVE-2019-12529EPSS 8%

An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authenticati…

Fix: 2.7+
Fix from $1,600 2019-07-11
Mongoose HIGH 7.5
CVE-2019-13503

mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.

Patch available
Fix from $1,950 2019-07-11
Debian Linux MEDIUM 6.5
CVE-2019-13504

There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.

Fix: after 0.27.2
Fix from $1,600 2019-07-11
Matrixssl CRITICAL 9.8
CVE-2019-13470

MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.

Fix: 4.2.1+
Fix from $2,300 2019-07-09
Android HIGH 7.5
CVE-2019-2116

In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disc…

Mitigation only
Fix from $1,950 2019-07-08
Imagemagick HIGH 8.8
CVE-2019-13391

In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrect calls to GetCacheViewVirtua…

Patch available
Fix from $1,950 2019-07-07
Ffmpeg HIGH 8.8
CVE-2019-13312

block_cmp() in libavcodec/zmbvenc.c in FFmpeg 4.1.3 has a heap-based buffer over-read.

Mitigation only
Fix from $1,950 2019-07-05
Debian Linux HIGH 8.8
CVE-2019-13297

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a height of zero is mishandled.

Patch available
Fix from $1,950 2019-07-05
Imagemagick HIGH 8.8
CVE-2019-13299

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/pixel-accessor.h in GetPixelChannel.

Patch available
Fix from $1,950 2019-07-05
Imagemagick HIGH 8.8
CVE-2019-13302

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/fourier.c in ComplexImages.

Patch available
Fix from $1,950 2019-07-05
Imagemagick HIGH 8.8
CVE-2019-13303

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read in MagickCore/composite.c in CompositeImage.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 8.8
CVE-2019-13295

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled.

Patch available
Fix from $1,950 2019-07-05
Fedora MEDIUM 5.5
CVE-2019-13286

In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for examp…

No fix yet
Fix from $1,600 2019-07-04
Xpdfreader MEDIUM 5.5
CVE-2019-13287

In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at splash/SplashXPath.cc. It can, f…

No fix yet
Fix from $1,600 2019-07-04
Xpdfreader MEDIUM 5.5
CVE-2019-13291

In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It can, for example, be triggered…

No fix yet
Fix from $1,600 2019-07-04
Fedora HIGH 7.8
CVE-2019-13282

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. …

No fix yet
Fix from $1,950 2019-07-04
Fedora HIGH 7.8
CVE-2019-13283

In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure th…

No fix yet
Fix from $1,950 2019-07-04
Alpha7 Pc Loader Firmware MEDIUM 6.6
CVE-2019-10975

An out-of-bounds read vulnerability has been identified in Fuji Electric Alpha7 PC Loader Versions 1.1 and prior, which may crash the system.

Fix: after 1.1
Fix from $1,600 2019-07-02
Fedora MEDIUM 6.5
CVE-2019-13110

A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSE…

Fix: after 0.27.1
Fix from $1,600 2019-06-30
Njs CRITICAL 9.8
CVE-2019-13067

njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is …

Fix: after 0.3.3
Fix from $2,300 2019-06-30
Webaccess HIGH 7.5
CVE-2019-10983

In WebAccess/SCADA Versions 8.3.5 and prior, an out-of-bounds read vulnerability is caused by a lack of proper validation of user-supplied data. Expl…

Fix: after 8.3.5
Fix from $1,950 2019-06-28
Chrome MEDIUM 6.5
CVE-2019-5835

Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory ac…

Fix: 75.0.3770.80+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-6129

Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory acc…

Fix: 67.0.3396.62+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-6130

Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bound…

Fix: 67.0.3396.62+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-6136

Missing type check in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML …

Fix: 67.0.3396.62+
Fix from $1,600 2019-06-27
Chrome MEDIUM 6.5
CVE-2018-6142

Array bounds check failure in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a craft…

Fix: 67.0.3396.62+
Fix from $1,600 2019-06-27