Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Imagemagick HIGH 8.1
CVE-2019-11597

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to caus…

No fix yet
Fix from $1,950 2019-04-29
Imagemagick HIGH 8.1
CVE-2019-11598

In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which allows an attacker to cause …

Patch available
Fix from $1,950 2019-04-29
Hhvm CRITICAL 9.8
CVE-2019-3561

Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM…

Fix: after 4.0.3
Fix from $2,300 2019-04-29
Cjson CRITICAL 9.8
CVE-2016-10749

parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with a " character and ends with a…

Fix: 0.0.0+
Fix from $2,300 2019-04-29
Debian Linux MEDIUM 5.3
CVE-2019-11579

dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.

Fix: 7.2.1+
Fix from $1,600 2019-04-28
Firefox HIGH 7.5
CVE-2019-9802

If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The d…

Fix: 66.0+
Fix from $1,950 2019-04-26
Firefox HIGH 7.5
CVE-2019-9799

Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the …

Fix: 66.0+
Fix from $1,950 2019-04-26
Graphicsmagick MEDIUM 6.5
CVE-2019-11473

coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by crafting an XWD ima…

Patch available
Fix from $1,600 2019-04-23
Debian Linux HIGH 8.1
CVE-2019-11455

A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of a…

Fix: 5.25.3+
Fix from $1,950 2019-04-22
Fedora MEDIUM 6.5
CVE-2019-11372

An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a …

Patch available
Fix from $1,600 2019-04-20
Fedora MEDIUM 6.5
CVE-2019-11373

An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.

Patch available
Fix from $1,600 2019-04-20
Android MEDIUM 5.0
CVE-2019-2039

In rw_i93_sm_detect_ndef of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disc…

Mitigation only
Fix from $1,600 2019-04-19
Android MEDIUM 5.0
CVE-2019-2040

In rw_i93_process_ext_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local informatio…

Mitigation only
Fix from $1,600 2019-04-19
Android HIGH 7.5
CVE-2019-2037

In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out-of-bound read due to an incorrect bounds check. This could lead to remote infor…

Patch available
Fix from $1,950 2019-04-19
Android MEDIUM 5.5
CVE-2019-2038

In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information di…

Patch available
Fix from $1,600 2019-04-19
Ffmpeg HIGH 8.8
CVE-2019-11339

The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote attackers to cause a denial of…

Fix: 4.0.4 / 4.1.2+
Fix from $1,950 2019-04-19
PHP CRITICAL 9.1
CVE-2019-11034

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past…

Fix: 7.1.28 / 7.2.17+
Fix from $2,300 2019-04-18
PHP CRITICAL 9.1
CVE-2019-11035

When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past…

Fix: 7.1.28 / 7.2.17+
Fix from $2,300 2019-04-18
Cncsoft Screeneditor MEDIUM 5.5
CVE-2019-10949

Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple out-of-bounds read vulnerabilities may be exploited, al…

Fix: after 1.00.88
Fix from $1,600 2019-04-17
Cp1604 Firmware HIGH 7.5
CVE-2019-6568

The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of ser…

Fix: 1.1.0 / 2.1.6+
Fix from $1,950 2019-04-17
Fusion MEDIUM 6.8
CVE-2019-5517

VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x…

Fix: 10.1.6 / 11.0.3+
Fix from $1,600 2019-04-15
Fusion MEDIUM 5.9
CVE-2019-5520

VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x…

Fix: 10.1.6 / 11.0.3+
Fix from $1,600 2019-04-15
Fusion MEDIUM 6.8
CVE-2019-5516

VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x before 14.1.6), Fusion (11.x…

Fix: 10.1.6 / 11.0.3+
Fix from $1,600 2019-04-15
Firefox HIGH 8.1
CVE-2017-7771

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.

Fix: 1.3.10 / 54.0+
Fix from $1,950 2019-04-15
Firefox CRITICAL 9.1
CVE-2017-7774

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.

Fix: 1.3.10 / 54.0+
Fix from $2,300 2019-04-15
Firefox HIGH 8.1
CVE-2017-7776

Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.

Fix: 1.3.10 / 54.0+
Fix from $1,950 2019-04-15
Linux Kernel MEDIUM 6.5
CVE-2019-3459

A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.

Fix: after 5.1
Fix from $1,600 2019-04-11
Wireshark HIGH 7.5
CVE-2019-10895EPSS 6%

In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wiretap/netscaler.c by improvin…

Fix: after 2.6.7
Fix from $1,950 2019-04-09
Wireshark HIGH 7.5
CVE-2019-10899EPSS 6%

In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/dissectors/packet-srvloc.c by p…

Fix: after 2.6.7
Fix from $1,950 2019-04-09
Wireshark HIGH 7.5
CVE-2019-10903EPSS 6%

In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerp…

Fix: after 2.6.7
Fix from $1,950 2019-04-09