Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Libsass MEDIUM 6.5
CVE-2019-6286

In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called from Sass::Parser::parse_impor…

No fix yet
Fix from $1,600 2019-01-14
Svgpp CRITICAL 9.8
CVE-2019-6246

An issue was discovered in SVG++ (aka svgpp) 1.2.3. After calling the gil::get_color function in Generic Image Library in Boost, the return code is u…

Patch available
Fix from $2,300 2019-01-13
Mac Os X MEDIUM 5.5
CVE-2018-4255

In macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.

Fix: 10.13.5+
Fix from $1,600 2019-01-11
Mac Os X MEDIUM 5.5
CVE-2018-4256

In macOS High Sierra before 10.13.5, an out-of-bounds read was addressed with improved input validation.

Fix: 10.13.5+
Fix from $1,600 2019-01-11
Iphone Os HIGH 8.8
CVE-2018-4194

In iOS before 11.4, iCloud for Windows before 7.5, watchOS before 4.3.1, iTunes before 12.7.5 for Windows, and macOS High Sierra before 10.13.5, an o…

Fix: 4.3.1 / 7.5+
Fix from $1,950 2019-01-11
Mac Os X CRITICAL 9.8
CVE-2018-4169

In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, an out-of-bounds read was addressed wi…

Fix: 10.13.3+
Fix from $2,300 2019-01-11
Chrome HIGH 8.8
CVE-2018-6151

Bad cast in DevTools in Google Chrome on Win, Linux, Mac, Chrome OS prior to 66.0.3359.117 allowed an attacker who convinced a user to install a mali…

Fix: 66.0.3359.117+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-6141

Insufficient validation of an image filter in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer …

Fix: 67.0.3396.62+
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-6143

Insufficient validation in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted …

Fix: 67.0.3396.62+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16082

An out of bounds read in Swiftshader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform out of bounds memory acc…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome HIGH 8.8
CVE-2018-16083EPSS 5%

An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out o…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-17461

An out of bounds read in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform an out of bounds memory read via a crafte…

Fix: 68.0.3440.75+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2017-15428EPSS 18%

Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3…

Fix: 62.0.3202.94+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2018-16076

Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted…

Fix: 69.0.3497.81+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2016-10403

Insufficient data validation on image data in PDFium in Google Chrome prior to 51.0.2704.63 allowed a remote attacker to perform an out of bounds mem…

Fix: 51.0.2704.63+
Fix from $1,950 2019-01-09
Chrome HIGH 8.8
CVE-2017-15401

A memory corruption bug in WebAssembly could lead to out of bounds read and write through V8 in WebAssembly in Google Chrome prior to 62.0.3202.62 al…

Fix: 62.0.3202.62+
Fix from $1,950 2019-01-09
Ubuntu Linux HIGH 7.5
CVE-2018-20679EPSS 8%

An issue was discovered in BusyBox before 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP server, client, and relay) allows a…

Fix: 1.30.0+
Fix from $1,950 2019-01-09
Ubuntu Linux HIGH 7.5
CVE-2019-5747

An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP client, server, and/or relay) migh…

Fix: after 1.30.0
Fix from $1,950 2019-01-09
Wireshark MEDIUM 5.5
CVE-2019-5718

In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by …

Fix: after 2.6.5
Fix from $1,600 2019-01-08
Foxit Reader HIGH 7.1
CVE-2019-5007

An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is an Out-of-Bounds Read Information Disclosure and crash due to a N…

Fix: 9.4+
Fix from $1,950 2019-01-03
Linux Kernel MEDIUM 5.5
CVE-2018-16885

A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer leng…

Fix: after 3.10.90
Fix from $1,600 2019-01-03
Libming MEDIUM 6.5
CVE-2019-3572

An issue was discovered in libming 0.4.8. There is a heap-based buffer over-read in the function writePNG in the file util/dbl2png.c of the dbl2png c…

No fix yet
Fix from $1,600 2019-01-02
Libsixel HIGH 7.8
CVE-2019-3574

In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by img2sixel.

No fix yet
Fix from $1,950 2019-01-02
Hhvm HIGH 8.1
CVE-2018-6340

The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server ho…

Fix: after 3.27.4
Fix from $1,950 2018-12-31
Ok File Formats HIGH 8.8
CVE-2018-20618

ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c.

Fix: after 2018-10-16
Fix from $1,950 2018-12-31
Libming MEDIUM 6.5
CVE-2018-20591

A heap-based buffer over-read was discovered in decompileJUMP function in util/decompile.c of libming v0.4.8. A crafted input can cause segmentation …

No fix yet
Fix from $1,600 2018-12-30
Otfcc MEDIUM 6.5
CVE-2018-20588

lib/support/unicodeconv/unicodeconv.c in libotfcc.a in otfcc v0.10.3-alpha has a buffer over-read.

No fix yet
Fix from $1,600 2018-12-30
Tcpreplay HIGH 7.8
CVE-2018-20552

Tcpreplay before 4.3.1 has a heap-based buffer over-read in packet2tree in tree.c.

Fix: 4.3.1+
Fix from $1,950 2018-12-28
Tcpreplay HIGH 7.8
CVE-2018-20553

Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.

Fix: 4.3.1+
Fix from $1,950 2018-12-28
Debian Linux MEDIUM 6.5
CVE-2018-20570

jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

No fix yet
Fix from $1,600 2018-12-28