Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Android MEDIUM 6.5
CVE-2018-9507

In bta_av_proc_meta_cmd of bta_av_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote informat…

Patch available
Fix from $1,600 2018-10-02
Android MEDIUM 6.5
CVE-2018-9508

In smp_process_keypress_notification of smp_act.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remot…

Patch available
Fix from $1,600 2018-10-02
Android MEDIUM 6.5
CVE-2018-9505

In mca_ccb_hdl_req of mca_cact.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclo…

Patch available
Fix from $1,600 2018-10-02
Android MEDIUM 6.5
CVE-2018-9506

In avrc_msg_cback of avrc_api.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to remote information disclosu…

Patch available
Fix from $1,600 2018-10-02
Android MEDIUM 6.5
CVE-2018-9502

In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote inform…

Patch available
Fix from $1,600 2018-10-02
Android HIGH 7.5
CVE-2018-9503

In rfc_process_mx_message of rfc_ts_frames.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote inform…

Patch available
Fix from $1,950 2018-10-02
Frenic Loader 3.3 Firmware CRITICAL 9.8
CVE-2018-14790EPSS 5%

Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. A buffer over-re…

Mitigation only
Fix from $2,300 2018-10-01
Frenic Loader 3.3 Firmware MEDIUM 5.3
CVE-2018-14798

Fuji Electric FRENIC LOADER v3.3 v7.3.4.1a of FRENIC-Mini (C1), FRENIC-Mini (C2), FRENIC-Eco, FRENIC-Multi, FRENIC-MEGA, FRENIC-Ace. The program does…

Mitigation only
Fix from $1,600 2018-10-01
Simdcomp MEDIUM 6.5
CVE-2018-17854

SIMDComp before 0.1.1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) because it can read (a…

Fix: 0.1.1+
Fix from $1,600 2018-10-01
Simdcomp MEDIUM 6.5
CVE-2018-17427

SIMDComp before 0.1.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) because it can read (a…

Fix: 0.1.0+
Fix from $1,600 2018-10-01
Tcpreplay HIGH 7.1
CVE-2018-17582

Tcpreplay v4.3.0 beta1 contains a heap-based buffer over-read. The get_next_packet() function in the send_packets.c file uses the memcpy() function u…

Patch available
Fix from $1,950 2018-09-28
Tcpreplay HIGH 7.1
CVE-2018-17580

A heap-based buffer over-read exists in the function fast_edit_packet() in the file send_packets.c of Tcpreplay v4.3.0 beta1. This can lead to Denial…

Patch available
Fix from $1,950 2018-09-28
Delta Industrial Automation Pmsoft MEDIUM 6.5
CVE-2018-14824

Delta Electronics Delta Industrial Automation PMSoft v2.11 or prior has an out-of-bounds read vulnerability that can be executed when processing proj…

Fix: after 2.11
Fix from $1,600 2018-09-27
V Server Firmware CRITICAL 9.8
CVE-2018-14819

Fuji Electric V-Server 4.0.3.0 and prior, An out-of-bounds read vulnerability has been identified, which may allow remote code execution.

Fix: after 4.0.3.0
Fix from $2,300 2018-09-26
Chrome MEDIUM 6.5
CVE-2018-6038

Heap buffer overflow in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted…

Fix: 64.0.3282.119+
Fix from $1,600 2018-09-25
Chrome HIGH 8.1
CVE-2018-6034

Insufficient data validation in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a…

Fix: 64.0.3282.119+
Fix from $1,950 2018-09-25
Acrobat Dc HIGH 7.5
CVE-2018-12850EPSS 34%

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read v…

Fix: after 18.011.20058
Fix from $1,950 2018-09-25
Acrobat Dc HIGH 7.5
CVE-2018-12775EPSS 7%

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read v…

Fix: after 18.011.20058
Fix from $1,950 2018-09-25
Acrobat Dc HIGH 7.5
CVE-2018-12778EPSS 7%

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read v…

Fix: after 18.011.20058
Fix from $1,950 2018-09-25
Acrobat Dc HIGH 7.5
CVE-2018-12801EPSS 7%

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read v…

Fix: after 18.011.20058
Fix from $1,950 2018-09-25
Acrobat Dc HIGH 7.5
CVE-2018-12840EPSS 29%

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read v…

Fix: after 18.011.20058
Fix from $1,950 2018-09-25
Acrobat Dc HIGH 7.5
CVE-2018-12849EPSS 34%

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds read v…

Fix: after 18.011.20058
Fix from $1,950 2018-09-25
Hdf5 MEDIUM 6.5
CVE-2018-17435

A heap-based buffer over-read in H5O_attr_decode() in H5Oattr.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service …

Fix: after 1.10.3
Fix from $1,600 2018-09-24
Binutils MEDIUM 5.5
CVE-2018-17360

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read …

Patch available
Fix from $1,600 2018-09-23
Ubuntu Linux HIGH 7.5
CVE-2018-14645

A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resu…

Fix: after 1.8.14
Fix from $1,950 2018-09-21
Webassembly Virtual Machine MEDIUM 6.5
CVE-2018-17292

An issue was discovered in WAVM before 2018-09-16. The loadModule function in Include/Inline/CLI.h lacks checking of the file length before a file ma…

Fix: 2018-09-16+
Fix from $1,600 2018-09-21
Ubuntu Linux MEDIUM 6.5
CVE-2018-17294

The matchCurrentInput function inside lou_translateString.c of Liblouis prior to 3.7 does not check the input string's length, allowing attackers to …

Fix: 3.7.0+
Fix from $1,600 2018-09-21
Mdm9206 Firmware HIGH 7.8
CVE-2018-11285

In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD …

Mitigation only
Fix from $1,950 2018-09-20
Mp4v2 MEDIUM 6.5
CVE-2018-17235

The function mp4v2::impl::MP4Track::FinishSdtp() in mp4track.cpp in libmp4v2 2.1.0 mishandles compatibleBrand while processing a crafted mp4 file, wh…

Mitigation only
Fix from $1,600 2018-09-20
Android HIGH 7.8
CVE-2018-11897

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing diag event after associa…

Patch available
Fix from $1,950 2018-09-19