Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Liblas MEDIUM 6.5
CVE-2018-20536

There is a heap-based buffer over-read at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of serv…

No fix yet
Fix from $1,600 2018-12-28
Radare2 MEDIUM 5.5
CVE-2018-20456

In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application cra…

Fix: 3.1.1+
Fix from $1,600 2018-12-25
Radare2 MEDIUM 5.5
CVE-2018-20457

In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via a…

Fix: after 3.1.3
Fix from $1,600 2018-12-25
Radare2 MEDIUM 5.5
CVE-2018-20458

In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a denial-of-service (application…

Fix: 3.1.1+
Fix from $1,600 2018-12-25
Radare2 MEDIUM 5.5
CVE-2018-20459

In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash…

Fix: after 3.1.3
Fix from $1,600 2018-12-25
Radare2 MEDIUM 5.5
CVE-2018-20461

In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (application crash caused by out-of-…

Fix: 3.1.1+
Fix from $1,600 2018-12-25
Libdoc MEDIUM 6.5
CVE-2018-20451

The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of servi…

Fix: after 2017-10-23
Fix from $1,600 2018-12-25
Libdoc MEDIUM 6.5
CVE-2018-20453

The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service …

Fix: after 20171023
Fix from $1,600 2018-12-25
Debian Linux MEDIUM 6.5
CVE-2018-20430

GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRAC…

Fix: after 1.8
Fix from $1,600 2018-12-24
Bento4 MEDIUM 6.5
CVE-2018-20409

An issue was discovered in Bento4 1.5.1-627. There is a heap-based buffer over-read in AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp, as demonstrated …

No fix yet
Fix from $1,600 2018-12-23
Ubuntu Linux MEDIUM 5.5
CVE-2018-20124

hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value.

Fix: after 3.1.0
Fix from $1,600 2018-12-20
Ubuntu Linux MEDIUM 6.5
CVE-2018-1000852

FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/…

Fix: 2.0.0+
Fix from $1,600 2018-12-20
Android HIGH 7.8
CVE-2018-11963

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overread may occur due to non-null …

Patch available
Fix from $1,950 2018-12-20
Espruino HIGH 7.8
CVE-2018-20201

There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or possibly u…

No fix yet
Fix from $1,950 2018-12-18
Debian Linux MEDIUM 5.3
CVE-2018-20185

In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which a…

Patch available
Fix from $1,600 2018-12-17
Yara MEDIUM 5.5
CVE-2018-19975

In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in libyara/exec.c. Specifically, OP_…

No fix yet
Fix from $1,600 2018-12-17
Ubuntu Linux HIGH 7.5
CVE-2018-20102

An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS resp…

Fix: after 1.8.14
Fix from $1,950 2018-12-12
Sinumerik 808d V4.7 Firmware HIGH 7.8
CVE-2018-11465

A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4…

Fix: after 4.8
Fix from $1,950 2018-12-12
Exiv2 MEDIUM 6.5
CVE-2018-20096

There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote …

Patch available
Fix from $1,600 2018-12-12
Exiv2 MEDIUM 6.5
CVE-2018-20098

There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote d…

Patch available
Fix from $1,600 2018-12-12
Chrome HIGH 8.8
CVE-2018-18359

Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory rea…

Fix: 71.0.3578.80+
Fix from $1,950 2018-12-11
Ubuntu Linux MEDIUM 6.5
CVE-2018-5811

An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an …

Fix: 0.18.9+
Fix from $1,600 2018-12-07
Ubuntu Linux MEDIUM 6.5
CVE-2017-16910

An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause …

Fix: 0.18.6+
Fix from $1,600 2018-12-07
Enterprise Linux Desktop HIGH 8.8
CVE-2018-5802

An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can…

Fix: 0.18.7+
Fix from $1,950 2018-12-07
Ubuntu Linux HIGH 8.8
CVE-2018-5807

An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-…

Fix: 0.18.9+
Fix from $1,950 2018-12-07
Perl CRITICAL 9.1
CVE-2018-18313EPSS 10%

Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory.

Fix: 5.26.3+
Fix from $2,300 2018-12-07
Android HIGH 7.5
CVE-2018-9562

In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parameter size. This could lead to remote information d…

Mitigation only
Fix from $1,950 2018-12-06
Android HIGH 7.5
CVE-2018-9565

In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure wi…

Mitigation only
Fix from $1,950 2018-12-06
Android MEDIUM 5.7
CVE-2018-9566

In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote inf…

Mitigation only
Fix from $1,600 2018-12-06
Android HIGH 7.8
CVE-2018-9538

In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a possible out of bounds read of a function pointer d…

Patch available
Fix from $1,950 2018-12-06