Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Clamav MEDIUM 5.5
CVE-2019-1798

A vulnerability in the Portable Executable (PE) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allo…

Fix: after 0.101.1
Fix from $1,600 2019-04-08
Debian Linux CRITICAL 9.1
CVE-2019-11006

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attac…

Fix: after 1.3.31
Fix from $2,300 2019-04-08
Debian Linux HIGH 8.1
CVE-2019-11007

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attacke…

Fix: after 1.3.31
Fix from $1,950 2019-04-08
Debian Linux HIGH 8.1
CVE-2019-11009

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attacke…

Fix: after 1.3.31
Fix from $1,950 2019-04-08
Clamav MEDIUM 5.5
CVE-2019-1786

A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and 0.101.0 could a…

Mitigation only
Fix from $1,600 2019-04-08
Debian Linux MEDIUM 5.5
CVE-2019-1787

A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could all…

Fix: after 0.101.1
Fix from $1,600 2019-04-08
Poppler MEDIUM 6.5
CVE-2019-10871

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.

No fix yet
Fix from $1,600 2019-04-05
Poppler HIGH 8.8
CVE-2019-10872

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.

No fix yet
Fix from $1,950 2019-04-05
Libhtp CRITICAL 9.8
CVE-2018-10243

htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization …

Mitigation only
Fix from $2,300 2019-04-04
Debian Linux HIGH 7.5
CVE-2018-10242

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the alloca…

Mitigation only
Fix from $1,950 2019-04-04
Mac Os X HIGH 7.1
CVE-2018-4434

An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.2.

Fix: 10.14.2+
Fix from $1,950 2019-04-03
Iphone Os MEDIUM 5.5
CVE-2018-4365

An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12.1.

Fix: 12.1+
Fix from $1,600 2019-04-03
Iphone Os HIGH 7.8
CVE-2018-4371

An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 12.1, macOS Mojave 10.14.1, tvOS 12.1, …

Fix: 5.1 / 10.14.1+
Fix from $1,950 2019-04-03
Mac Os X MEDIUM 5.5
CVE-2018-4308

An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to macOS Mojave 10.14.

Fix: 10.14+
Fix from $1,600 2019-04-03
Iphone Os MEDIUM 5.5
CVE-2018-4282

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue affect…

Fix: 4.3.2 / 11.4.1+
Fix from $1,600 2019-04-03
Mac Os X MEDIUM 5.5
CVE-2018-4283

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue affect…

Fix: 10.13.6+
Fix from $1,600 2019-04-03
Iphone Os HIGH 7.5
CVE-2018-4203

An out-of-bounds read was addressed with improved bounds checking. This issue affected versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, watchOS…

Fix: 5.0 / 10.14+
Fix from $1,950 2019-04-03
Iphone Os HIGH 7.5
CVE-2018-4248

An out-of-bounds read was addressed with improved input validation. This issue affected versions prior to iOS 11.4.1, macOS High Sierra 10.13.6, tvOS…

Fix: 4.3.2 / 10.13.6+
Fix from $1,950 2019-04-03
Imagemagick MEDIUM 6.5
CVE-2019-10714

LocaleLowercase in MagickCore/locale.c in ImageMagick before 7.0.8-32 allows out-of-bounds access, leading to a SIGSEGV.

Fix: 6.9.10-32 / 7.0.8-32+
Fix from $1,600 2019-04-02
Fusion MEDIUM 6.8
CVE-2019-5518

VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.x before 15.0.4, 14.x before …

Fix: 10.1.6 / 11.0.3+
Fix from $1,600 2019-04-01
Long Range Zip MEDIUM 5.5
CVE-2019-10654

The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote attackers to cause a denial of …

No fix yet
Fix from $1,600 2019-03-30
Debian Linux HIGH 8.1
CVE-2019-10650

In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to caus…

Patch available
Fix from $1,950 2019-03-30
Pi Studio MEDIUM 6.5
CVE-2018-14814

WECON Technology PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior lacks proper validation of user-supplied data, which …

Fix: after 4.2.34
Fix from $1,600 2019-03-27
Laquis Scada HIGH 7.1
CVE-2018-18994

LCDS Laquis SCADA prior to version 4.1.0.4150 allows an out of bounds read when opening a specially crafted project file, which may cause a system cr…

Fix: 4.1.0.4150+
Fix from $1,950 2019-03-27
Rslinx Enterprise HIGH 7.5
CVE-2013-2805

Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 doe…

Mitigation only
Fix from $1,950 2019-03-26
Rslinx Enterprise HIGH 7.5
CVE-2013-2807

Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 doe…

Mitigation only
Fix from $1,950 2019-03-26
Debian Linux CRITICAL 9.1
CVE-2019-3860EPSS 5%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compr…

Fix: after 1.8.0
Fix from $2,300 2019-03-25
Debian Linux CRITICAL 9.1
CVE-2019-3861EPSS 5%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length a…

Fix: after 1.8.0
Fix from $2,300 2019-03-25
SQLite HIGH 7.5
CVE-2019-9936

In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, whi…

Patch available
Fix from $1,950 2019-03-22
Fedora CRITICAL 9.1
CVE-2019-3858EPSS 6%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker…

Fix: 1.8.1+
Fix from $2,300 2019-03-21