Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Freeware Advanced Audio Decoder 2 HIGH 7.8
CVE-2018-19504

An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There is a NULL pointer dereference in ifilter_bank() in libfaad/filtbank…

No fix yet
Fix from $1,950 2018-11-23
Sysstat HIGH 7.8
CVE-2018-19416

An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memmove call, as demonstrated …

No fix yet
Fix from $1,950 2018-11-21
Foxit Reader MEDIUM 5.5
CVE-2018-19388

FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read, access violation, and applicati…

No fix yet
Fix from $1,600 2018-11-20
Foxit Reader MEDIUM 5.5
CVE-2018-19389

FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Break instruction exception and application crash) …

No fix yet
Fix from $1,600 2018-11-20
Foxit Reader MEDIUM 5.5
CVE-2018-19390

FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Break instruction exception and application crash) …

No fix yet
Fix from $1,600 2018-11-20
Libansilove MEDIUM 6.5
CVE-2018-19353

The ansilove_ansi function in loaders/ansi.c in libansilove 1.0.0 allows remote attackers to cause a denial of service (out-of-bounds read and applic…

No fix yet
Fix from $1,600 2018-11-18
Foxit Reader HIGH 7.1
CVE-2018-19341

The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,950 2018-11-17
Foxit Reader HIGH 7.1
CVE-2018-19342

The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,950 2018-11-17
Foxit Reader HIGH 7.1
CVE-2018-19343

The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,950 2018-11-17
Foxit Reader HIGH 7.1
CVE-2018-19344

The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,950 2018-11-17
Foxit Reader HIGH 7.1
CVE-2018-19345

The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,950 2018-11-17
Foxit Reader HIGH 7.1
CVE-2018-19346

The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,950 2018-11-17
Foxit Reader HIGH 7.1
CVE-2018-19347

The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,950 2018-11-17
Foxit Reader HIGH 7.1
CVE-2018-19348

The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,950 2018-11-17
Ubuntu Linux MEDIUM 5.5
CVE-2018-18954

The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.

Fix: 3.1+
Fix from $1,600 2018-11-15
Harfbuzz MEDIUM 6.5
CVE-2015-9274

HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB…

Fix: 1.0.4+
Fix from $1,600 2018-11-15
Android HIGH 7.5
CVE-2018-9541

In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote informati…

Patch available
Fix from $1,950 2018-11-14
Android HIGH 7.5
CVE-2018-9542

In avrc_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informati…

Patch available
Fix from $1,950 2018-11-14
Android MEDIUM 5.5
CVE-2018-9544

In register_app of btif_hd.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure …

Patch available
Fix from $1,600 2018-11-14
Android HIGH 7.5
CVE-2018-9540

In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote infor…

Patch available
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-6067

Incorrect IPC serialization in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a cr…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome MEDIUM 6.5
CVE-2018-6069

Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted…

Fix: 65.0.3325.146+
Fix from $1,600 2018-11-14
Chrome HIGH 8.8
CVE-2018-6071

An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted H…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-17466

Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a cr…

Fix: 70.0.3538.67+
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-17469

Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory…

Fix: 70.0.3538.67+
Fix from $1,950 2018-11-14
Enterprise Linux HIGH 7.8
CVE-2018-19214

Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.

Patch available
Fix from $1,950 2018-11-12
Enterprise Linux HIGH 7.8
CVE-2018-19215

Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and !…

No fix yet
Fix from $1,950 2018-11-12
Libsass MEDIUM 6.5
CVE-2018-19218

In LibSass 3.5-stable, there is an illegal address access at Sass::Parser::parse_css_variable_value_token that will lead to a DoS attack.

No fix yet
Fix from $1,600 2018-11-12
Libav MEDIUM 6.5
CVE-2018-19128

In Libav 12.3, there is a heap-based buffer over-read in decode_frame in libavcodec/lcldec.c that allows an attacker to cause denial-of-service via a…

Mitigation only
Fix from $1,600 2018-11-09
Debian Linux MEDIUM 6.5
CVE-2018-19107

In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-bas…

Patch available
Fix from $1,600 2018-11-08