Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Matio CRITICAL 9.1
CVE-2019-9033

An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read for the "Rank and Dimension…

No fix yet
Fix from $2,300 2019-02-23
Matio CRITICAL 9.1
CVE-2019-9034

An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read for a memcpy in the functio…

No fix yet
Fix from $2,300 2019-02-23
Matio CRITICAL 9.1
CVE-2019-9035

An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function ReadNextStr…

No fix yet
Fix from $2,300 2019-02-23
PHP CRITICAL 9.8
CVE-2019-9020EPSS 10%

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_de…

Fix: 5.6.40 / 7.1.26+
Fix from $2,300 2019-02-22
PHP CRITICAL 9.8
CVE-2019-9021EPSS 10%

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR r…

Fix: 5.6.40 / 7.1.26+
Fix from $2,300 2019-02-22
PHP HIGH 7.5
CVE-2019-9022

An issue was discovered in PHP 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.2. dns_get_record misparses a DNS response, which can all…

Fix: 7.1.26 / 7.2.14+
Fix from $1,950 2019-02-22
PHP CRITICAL 9.8
CVE-2019-9023EPSS 9%

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read…

Fix: 5.6.40 / 7.1.26+
Fix from $2,300 2019-02-22
PHP HIGH 7.5
CVE-2019-9024EPSS 7%

An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. xmlrpc_decode() can allow a hostile XML…

Fix: 5.6.40 / 7.1.26+
Fix from $1,950 2019-02-22
PHP CRITICAL 9.8
CVE-2019-9025

An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php…

Fix: 7.3.1+
Fix from $2,300 2019-02-22
PHP HIGH 7.5
CVE-2018-20783EPSS 6%

In PHP before 5.6.39, 7.x before 7.0.33, 7.1.x before 7.1.25, and 7.2.x before 7.2.13, a buffer over-read in PHAR reading functions may allow an atta…

Fix: 5.6.39 / 7.0.33+
Fix from $1,950 2019-02-21
Chrome HIGH 8.8
CVE-2019-5782EPSS 13%

Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox …

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Chrome HIGH 8.8
CVE-2019-5770

Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a…

Fix: 72.0.3626.81+
Fix from $1,950 2019-02-19
Fedora MEDIUM 5.5
CVE-2019-3812

QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() fun…

Fix: after 3.1.0
Fix from $1,600 2019-02-19
Ubuntu Linux HIGH 8.8
CVE-2019-8904

do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf.

No fix yet
Fix from $1,950 2019-02-18
Hdf5 MEDIUM 6.5
CVE-2019-8397

An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_close_real in H5T.c.

No fix yet
Fix from $1,600 2019-02-17
Hdf5 MEDIUM 6.5
CVE-2019-8398

An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_get_size in H5T.c.

No fix yet
Fix from $1,600 2019-02-17
Bento4 HIGH 8.8
CVE-2019-8378

An issue was discovered in Bento4 1.5.1-628. A heap-based buffer over-read exists in AP4_BitStream::ReadBytes() in Codecs/Ap4BitStream.cpp, a similar…

No fix yet
Fix from $1,950 2019-02-17
Cx Supervisor MEDIUM 5.0
CVE-2018-19020

When CX-Supervisor (Versions 3.42 and prior) processes project files and tampers with the value of an offset, an attacker can force the application t…

Fix: after 3.42
Fix from $1,600 2019-02-12
Android MEDIUM 6.5
CVE-2018-9588

In avdt_scb_hdl_report of avdt_scb_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible o…

Mitigation only
Fix from $1,600 2019-02-11
Android MEDIUM 5.5
CVE-2018-9589

In ieee802_11_rx_wnmsleep_req of wnm_ap.c in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible o…

Patch available
Fix from $1,600 2019-02-11
Android HIGH 7.5
CVE-2018-9590

In add_attr of sdp_discovery.c in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bound…

Patch available
Fix from $1,950 2019-02-11
Android HIGH 7.5
CVE-2018-9591

In bta_hh_ctrl_dat_act of bta_hh_act.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out…

Mitigation only
Fix from $1,950 2019-02-11
Android HIGH 7.5
CVE-2018-9592

In mca_ccb_hdl_rsp of mca_cact.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bo…

Mitigation only
Fix from $1,950 2019-02-11
Android MEDIUM 6.5
CVE-2018-9593

In llcp_dlc_proc_i_pdu of llcp_dlc.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out o…

Mitigation only
Fix from $1,600 2019-02-11
Android MEDIUM 6.5
CVE-2018-9594

In llcp_link_proc_agf_pdu of llcp_link.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible o…

Mitigation only
Fix from $1,600 2019-02-11
Bento4 MEDIUM 6.5
CVE-2019-7699

A heap-based buffer over-read occurs in AP4_BitStream::WriteBytes in Codecs/Ap4BitStream.cpp in Bento4 v1.5.1-627. Remote attackers could leverage th…

No fix yet
Fix from $1,600 2019-02-10
Binaryen MEDIUM 6.5
CVE-2019-7700

A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22. A crafted wasm input can c…

Fix: 64+
Fix from $1,600 2019-02-10
Binaryen MEDIUM 6.5
CVE-2019-7701

A heap-based buffer over-read was discovered in wasm::SExpressionParser::skipWhitespace() in wasm-s-parser.cpp in Binaryen 1.38.22. A crafted wasm in…

Fix: 64+
Fix from $1,600 2019-02-10
Debian Linux MEDIUM 5.5
CVE-2019-7665

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can…

No fix yet
Fix from $1,600 2019-02-09
Debian Linux HIGH 8.1
CVE-2019-7635

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-08