Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Libsass MEDIUM 6.5
CVE-2018-19839

In LibSass prior to 3.5.5, the function handle_error in sass_context.cpp allows attackers to cause a denial-of-service resulting from a heap-based bu…

Fix: 3.5.5+
Fix from $1,600 2018-12-04
Ubuntu Linux MEDIUM 5.5
CVE-2018-19841

The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-…

Fix: after 5.1.0
Fix from $1,600 2018-12-04
Radare2 MEDIUM 5.5
CVE-2018-19842

getToken in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (stack-based buffer over-read) via crafted …

Fix: 3.1.0+
Fix from $1,600 2018-12-04
Radare2 MEDIUM 5.5
CVE-2018-19843

opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (buffer over-read) via crafted x86 assembly da…

Fix: 3.1.1+
Fix from $1,600 2018-12-04
Recursor HIGH 7.5
CVE-2018-16855EPSS 59%

An issue has been found in PowerDNS Recursor before version 4.1.8 where a remote attacker sending a DNS query can trigger an out-of-bounds memory rea…

Fix: 4.1.8+
Fix from $1,950 2018-12-03
Libsixel MEDIUM 5.5
CVE-2018-19756

There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a denial of service.

No fix yet
Fix from $1,600 2018-11-30
Debian Linux MEDIUM 6.5
CVE-2018-19758

There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.

No fix yet
Fix from $1,600 2018-11-30
Libsixel MEDIUM 5.5
CVE-2018-19759

There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a denial of service.

No fix yet
Fix from $1,600 2018-11-30
Libsixel MEDIUM 5.5
CVE-2018-19761

There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a denial of service.

No fix yet
Fix from $1,600 2018-11-30
Libsixel MEDIUM 5.5
CVE-2018-19763

There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a denial of service.

No fix yet
Fix from $1,600 2018-11-30
Debian Linux MEDIUM 6.5
CVE-2018-19497

In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows atta…

Fix: after 4.6.4
Fix from $1,600 2018-11-29
Enterprise Linux Desktop HIGH 7.5
CVE-2018-15978EPSS 7%

Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 31.0.0.122
Fix from $1,950 2018-11-29
Photoshop Cc HIGH 7.5
CVE-2018-15980EPSS 8%

Adobe Photoshop CC versions 19.1.6 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 19.1.6
Fix from $1,950 2018-11-29
Ubuntu Linux HIGH 7.5
CVE-2018-8789EPSS 5%

FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfau…

Fix: after 1.2.0
Fix from $1,950 2018-11-29
Debian Linux MEDIUM 6.5
CVE-2018-19661

An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of servic…

No fix yet
Fix from $1,600 2018-11-29
Debian Linux HIGH 8.1
CVE-2018-19662

An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of servic…

Patch available
Fix from $1,950 2018-11-29
Libjpeg Turbo MEDIUM 6.5
CVE-2018-19664

libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg.

No fix yet
Fix from $1,600 2018-11-29
Wireshark MEDIUM 5.5
CVE-2018-19625

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the dissection engine could crash. This was addressed in epan/tvbuff_composite.c by preventing a hea…

Fix: after 2.6.4
Fix from $1,600 2018-11-29
Wireshark MEDIUM 5.5
CVE-2018-19626

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' t…

Fix: after 2.6.4
Fix from $1,600 2018-11-29
Wireshark HIGH 7.5
CVE-2018-19627EPSS 18%

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer bo…

Fix: after 2.6.4
Fix from $1,950 2018-11-29
Sd 600 Firmware HIGH 7.8
CVE-2017-18315

Buffer over-read vulnerabilities in an older version of ASN.1 parser in Snapdragon Mobile in versions SD 600.

No fix yet
Fix from $1,950 2018-11-28
Mdm9206 Firmware MEDIUM 6.5
CVE-2018-5916

Buffer overread while decoding PDP modify request or network initiated secondary PDP activation in Snapdragon Automobile, Snapdragon Mobile and Snapd…

Mitigation only
Fix from $1,600 2018-11-28
Android HIGH 7.8
CVE-2017-11078

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the boot image header, an…

Patch available
Fix from $1,950 2018-11-27
Dcraw HIGH 7.1
CVE-2018-19565

A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that…

Fix: after 9.28
Fix from $1,950 2018-11-26
Dcraw HIGH 7.1
CVE-2018-19566

A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application tha…

Fix: after 9.28
Fix from $1,950 2018-11-26
Ubuntu Linux HIGH 8.8
CVE-2018-19541

An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.1…

No fix yet
Fix from $1,950 2018-11-26
Ubuntu Linux HIGH 7.8
CVE-2018-19543

An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.

No fix yet
Fix from $1,950 2018-11-26
Debian Linux MEDIUM 6.5
CVE-2018-19535

In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-base…

Fix: after 0.26
Fix from $1,600 2018-11-26
Tcpdump MEDIUM 5.5
CVE-2018-19519

In tcpdump 4.9.2, a stack-based buffer over-read exists in the print_prefix function of print-hncp.c via crafted packet data because of missing initi…

No fix yet
Fix from $1,600 2018-11-25
Sysstat MEDIUM 5.5
CVE-2018-19517

An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memset call, as demonstrated b…

No fix yet
Fix from $1,600 2018-11-24