Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Acrobat Dc HIGH 7.5
CVE-2019-7142

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 201…

Fix: after 19.010.20100
Fix from $1,950 2019-05-22
Acrobat Dc HIGH 8.8
CVE-2019-7143EPSS 9%

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 201…

Fix: after 19.010.20100
Fix from $1,950 2019-05-22
Acrobat Dc MEDIUM 6.5
CVE-2019-7144EPSS 9%

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 201…

Fix: after 19.010.20100
Fix from $1,600 2019-05-22
Acrobat Dc MEDIUM 6.5
CVE-2019-7145EPSS 9%

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 201…

Fix: after 19.010.20100
Fix from $1,600 2019-05-22
Acrobat Dc MEDIUM 6.5
CVE-2019-7758EPSS 9%

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earl…

Fix: after 19.010.20100
Fix from $1,600 2019-05-22
Acrobat Dc MEDIUM 6.5
CVE-2019-7141EPSS 9%

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 201…

Fix: after 19.010.20100
Fix from $1,600 2019-05-22
Acrobat Dc MEDIUM 6.5
CVE-2019-7140EPSS 9%

Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 201…

Fix: after 19.010.20100
Fix from $1,600 2019-05-22
Sdl2 Image MEDIUM 6.5
CVE-2019-12220

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There…

No fix yet
Fix from $1,600 2019-05-20
Simple Directmedia Layer MEDIUM 6.5
CVE-2019-12222

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9. There is an out-of-bounds read in the function SDL_InvalidateMap at vid…

No fix yet
Fix from $1,600 2019-05-20
Freeimage HIGH 7.5
CVE-2019-12214

In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ppm_v3 function in j2k.c. The value of l_N_ppm co…

No fix yet
Fix from $1,950 2019-05-20
Njs CRITICAL 9.8
CVE-2019-12207

njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c.

Fix: after 0.3.1
Fix from $2,300 2019-05-20
Gohttp HIGH 7.5
CVE-2019-12198

In GoHttp through 2017-07-25, there is a stack-based buffer over-read via a long User-Agent header.

Fix: after 20170725
Fix from $1,950 2019-05-20
Gohttp HIGH 7.5
CVE-2019-12159

GoHTTP through 2017-07-25 has a stack-based buffer over-read in the scan function (when called from getRequestType) via a long URL.

Fix: after 2017-07-25
Fix from $1,950 2019-05-17
Anyconnect Secure Mobility Client HIGH 7.5
CVE-2019-1853

A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to rea…

Mitigation only
Fix from $1,950 2019-05-16
Capstone MEDIUM 5.5
CVE-2016-7151

Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caused by a read memory access) in X86_insn_reg_intel in arch/X86/X86Mapping.c.

Patch available
Fix from $1,600 2019-05-15
Suricata CRITICAL 9.8
CVE-2019-10053

An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of a \n character, then the prog…

Fix: 4.1.4+
Fix from $2,300 2019-05-13
Rust HIGH 8.1
CVE-2019-12083

The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guar…

Fix: 1.34.2+
Fix from $1,950 2019-05-13
Suricata HIGH 7.5
CVE-2019-10050

A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-mpls.c function DecodeMPLS is composed only of a p…

Fix: 4.1.4+
Fix from $1,950 2019-05-13
Gpu Driver MEDIUM 5.5
CVE-2019-5677

NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for De…

Mitigation only
Fix from $1,600 2019-05-10
Mpg123 HIGH 8.3
CVE-2017-12839

A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible…

Fix: after 1.25.5
Fix from $1,950 2019-05-09
Cjson CRITICAL 9.8
CVE-2019-11834

cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.

Fix: 1.7.11 / 18.1.3.1.0+
Fix from $2,300 2019-05-09
Cjson CRITICAL 9.8
CVE-2019-11835

cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.

Fix: 1.7.11 / 18.1.3.1.0+
Fix from $2,300 2019-05-09
Android HIGH 7.5
CVE-2019-2051

In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure when p…

Mitigation only
Fix from $1,950 2019-05-08
Android HIGH 7.5
CVE-2019-2052

In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This could lead to remote information disclosure with no a…

Mitigation only
Fix from $1,950 2019-05-08
Android MEDIUM 5.5
CVE-2019-2053

In wnm_parse_neighbor_report_elem of wnm_sta.c, there is a possible out-of-bounds read due to missing bounds check. This could lead to local informat…

Mitigation only
Fix from $1,600 2019-05-08
Mqtt Packet HIGH 7.5
CVE-2019-5432

A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.…

Fix: 3.5.1+
Fix from $1,950 2019-05-06
Debian Linux CRITICAL 9.8
CVE-2019-11766

dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.

Fix: 6.11.7 / 7.2.2+
Fix from $2,300 2019-05-05
PHP CRITICAL 9.1
CVE-2019-11036EPSS 7%

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past…

Fix: 7.1.29 / 7.2.18+
Fix from $2,300 2019-05-03
Recutils MEDIUM 6.5
CVE-2019-11637

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leadin…

No fix yet
Fix from $1,600 2019-05-01
Recutils MEDIUM 6.5
CVE-2019-11638

An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec…

No fix yet
Fix from $1,600 2019-05-01