Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Android HIGH 7.8
CVE-2018-11898

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing start bss request from u…

Patch available
Fix from $1,950 2018-09-19
Android HIGH 7.8
CVE-2018-11297

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a buffer over-read can occur In the WMA N…

Patch available
Fix from $1,950 2018-09-18
Android MEDIUM 5.7
CVE-2018-11293

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, in wma_ndp_confirm_event_handler and wma_…

Patch available
Fix from $1,600 2018-09-18
Android HIGH 7.1
CVE-2018-11278

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Venus HW searches for start code when dec…

Patch available
Fix from $1,950 2018-09-18
Android HIGH 7.8
CVE-2017-15825

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing a gpt update, an out of …

Patch available
Fix from $1,950 2018-09-18
Android MEDIUM 5.5
CVE-2017-15844

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the function for writing…

Patch available
Fix from $1,600 2018-09-18
Json\+\+ CRITICAL 9.8
CVE-2018-17072

JSON++ through 2016-06-15 has a buffer over-read in yyparse() in json.y.

Fix: after 2016-06-15
Fix from $2,300 2018-09-16
Bsafe CRITICAL 9.8
CVE-2018-11058

RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior…

Fix: 4.0.5.3 / 4.0.11+
Fix from $2,300 2018-09-14
Lizard HIGH 7.5
CVE-2018-16985

In Lizard (formerly LZ5) 2.0, use of an invalid memory address was discovered in LZ5_compress_continue in lz5_compress.c, related to LZ5_compress_fas…

No fix yet
Fix from $1,950 2018-09-13
Open Chinese Convert MEDIUM 5.5
CVE-2018-16982

Open Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial of service (segmentation fault) because BinaryDict::NewFromFile in BinaryDict.…

No fix yet
Fix from $1,600 2018-09-13
Libbson HIGH 8.1
CVE-2018-16790

_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read vi…

Patch available
Fix from $1,950 2018-09-10
Webassembly Virtual Machine HIGH 8.8
CVE-2018-16764

In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have…

Fix: after 2018-07-26
Fix from $1,950 2018-09-10
Contiki Ng. HIGH 7.0
CVE-2018-16667

An issue was discovered in Contiki-NG through 4.1. There is a buffer over-read in lookup in os/storage/antelope/lvm.c while parsing AQL (lvm_register…

Fix: after 4.1
Fix from $1,950 2018-09-07
Jsish MEDIUM 6.5
CVE-2018-1000668

jsish version 2.4.70 2.047 contains a CWE-125: Out-of-bounds Read vulnerability in function jsi_ObjArrayLookup (jsiObj.c:274) that can result in Cras…

Patch available
Fix from $1,600 2018-09-06
Hdf5 HIGH 8.8
CVE-2018-16438

An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in H5L_extern_query at H5Lexternal.c.

No fix yet
Fix from $1,950 2018-09-04
Ubuntu Linux HIGH 7.5
CVE-2018-16429

GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().

Patch available
Fix from $1,950 2018-09-04
Debian Linux HIGH 8.8
CVE-2018-16430

GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.

Fix: after 1.7
Fix from $1,950 2018-09-04
Imagemagick HIGH 8.8
CVE-2018-16412

ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the coders/psd.c ParseImageResourceBlocks function.

No fix yet
Fix from $1,950 2018-09-03
Imagemagick HIGH 8.8
CVE-2018-16413

ImageMagick 7.0.8-11 Q16 has a heap-based buffer over-read in the MagickCore/quantum-private.h PushShortPixel function when called from the coders/ps…

No fix yet
Fix from $1,950 2018-09-03
Elfutils MEDIUM 5.5
CVE-2018-16403

libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.…

No fix yet
Fix from $1,600 2018-09-03
Netwide Assembler MEDIUM 5.5
CVE-2018-16382

Netwide Assembler (NASM) 2.14rc15 has a buffer over-read in x86/regflags.c.

No fix yet
Fix from $1,600 2018-09-03
Xpdf MEDIUM 5.5
CVE-2018-16368

SplashXPath::strokeAdjust in splash/SplashXPath.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (heap-based buffer over-read) vi…

No fix yet
Fix from $1,600 2018-09-03
Ubuntu Linux MEDIUM 6.5
CVE-2018-16336

Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a craf…

Mitigation only
Fix from $1,600 2018-09-02
Libfsclfs MEDIUM 6.5
CVE-2018-15157

The libfsclfs_block_read function in libfsclfs_block.c in libfsclfs before 2018-07-25 allows remote attackers to cause a heap-based buffer over-read …

Fix: 2018-07-25+
Fix from $1,600 2018-09-01
Libesedb MEDIUM 6.5
CVE-2018-15158

The libesedb_page_read_values function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-re…

Fix: after 2018-04-01
Fix from $1,600 2018-09-01
Libesedb MEDIUM 6.5
CVE-2018-15159

The libesedb_page_read_tags function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read…

Fix: after 2018-04-01
Fix from $1,600 2018-09-01
Libesedb MEDIUM 6.5
CVE-2018-15160

The libesedb_catalog_definition_read function in libesedb_catalog_definition.c in libesedb through 2018-04-01 allows remote attackers to cause a heap…

Fix: after 2018-04-01
Fix from $1,600 2018-09-01
Libesedb MEDIUM 6.5
CVE-2018-15161

The libesedb_key_append_data function in libesedb_key.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read…

Fix: after 2018-04-01
Fix from $1,600 2018-09-01
Antivirus \+ Security HIGH 7.8
CVE-2018-15363

An Out-of-Bounds Read Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to escalate pr…

Fix: after 12.0
Fix from $1,950 2018-08-30
Enterprise Linux Desktop HIGH 7.5
CVE-2018-12826EPSS 7%

Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 30.0.0.154
Fix from $1,950 2018-08-29