Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Xpdf HIGH 7.8
CVE-2019-9877

There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf 4.01, which can (for example)…

No fix yet
Fix from $1,950 2019-03-21
Pdfalto HIGH 7.8
CVE-2019-9878

There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf 4.0.0, as used in pdfalto 0.2…

No fix yet
Fix from $1,950 2019-03-21
Phantompdf MEDIUM 6.5
CVE-2019-6733

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is req…

Fix: after 9.3.0.10826
Fix from $1,600 2019-03-21
Phantompdf MEDIUM 6.5
CVE-2019-6735

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is require…

Fix: after 9.3.0.10826
Fix from $1,600 2019-03-21
Phantompdf MEDIUM 6.5
CVE-2019-6728

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader. User interaction is require…

Fix: after 9.3.0.10826
Fix from $1,600 2019-03-21
Phantompdf HIGH 8.8
CVE-2019-6729

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User interaction is required to exp…

Fix: after 9.3.0.10826
Fix from $1,950 2019-03-21
Phantompdf HIGH 8.8
CVE-2019-6731

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF. User interaction is required to…

Fix: after 9.3.0.10826
Fix from $1,950 2019-03-21
Phantompdf MEDIUM 6.5
CVE-2019-6732

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit PhantomPDF. User interaction is req…

Fix: after 9.3.0.10826
Fix from $1,600 2019-03-21
Fedora MEDIUM 5.5
CVE-2019-6501

In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.

Patch available
Fix from $1,600 2019-03-21
Debian Linux MEDIUM 5.5
CVE-2019-3832

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header(…

Patch available
Fix from $1,600 2019-03-21
Fedora CRITICAL 9.1
CVE-2019-3859EPSS 6%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote att…

Fix: 1.8.1+
Fix from $2,300 2019-03-21
Fedora CRITICAL 9.1
CVE-2019-3862EPSS 8%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no paylo…

Fix: 1.8.1+
Fix from $2,300 2019-03-21
Ubuntu Linux HIGH 7.5
CVE-2018-20615

An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The p…

Fix: after 1.8.19
Fix from $1,950 2019-03-21
Fedora MEDIUM 5.5
CVE-2018-18849

In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.

Patch available
Fix from $1,600 2019-03-21
Rdesktop HIGH 7.5
CVE-2018-20174

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function ui_clip_handle_data() that results in an information leak.

Fix: after 1.8.3
Fix from $1,950 2019-03-15
Debian Linux HIGH 7.5
CVE-2018-20175

rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result…

Fix: after 1.8.3
Fix from $1,950 2019-03-15
Rdesktop HIGH 7.5
CVE-2018-20176

rdesktop versions up to and including v1.8.3 contain several Out-Of- Bounds Reads in the file secure.c that result in a Denial of Service (segfault).

Fix: after 1.8.3
Fix from $1,950 2019-03-15
Debian Linux HIGH 7.5
CVE-2018-20178

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Servic…

Fix: after 1.8.3
Fix from $1,950 2019-03-15
Graphics Driver MEDIUM 5.5
CVE-2018-18089

Multiple out of bounds read in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (ak…

Patch available
Fix from $1,600 2019-03-14
Graphics Driver MEDIUM 5.5
CVE-2018-18090

Out of bounds read in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x…

Patch available
Fix from $1,600 2019-03-14
Libredwg HIGH 7.5
CVE-2019-9777

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write at header_variables…

No fix yet
Fix from $1,950 2019-03-14
Libredwg HIGH 7.5
CVE-2019-9778

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at dwg.spec.

No fix yet
Fix from $1,950 2019-03-14
Libredwg CRITICAL 9.1
CVE-2019-9774

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c.

No fix yet
Fix from $2,300 2019-03-14
Libredwg CRITICAL 9.1
CVE-2019-9775

An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at dwg.spec.

No fix yet
Fix from $2,300 2019-03-14
Tinysvcmdns CRITICAL 9.1
CVE-2019-9748

In tinysvcmdns through 2018-01-16, an mDNS server processing a crafted packet can perform arbitrary data read operations up to 16383 bytes from the s…

Fix: after 2018-01-16
Fix from $2,300 2019-03-13
Debian Linux MEDIUM 6.5
CVE-2019-9718

In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, becau…

Patch available
Fix from $1,600 2019-03-12
Ubuntu Linux MEDIUM 6.5
CVE-2019-9721

A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video file in Matroska format, becaus…

Patch available
Fix from $1,600 2019-03-12
PHP HIGH 7.5
CVE-2019-9638EPSS 7%

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in ex…

Fix: 7.1.27 / 7.2.16+
Fix from $1,950 2019-03-09
PHP HIGH 7.5
CVE-2019-9640EPSS 6%

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_pro…

Fix: 7.1.27 / 7.2.16+
Fix from $1,950 2019-03-09
Ultravnc CRITICAL 9.8
CVE-2019-8264

UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. Th…

Fix: 1.2.2.3+
Fix from $2,300 2019-03-08