Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Radare2 MEDIUM 5.5
CVE-2018-12322

There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a crafted iNES ROM binary file.

Patch available
Fix from $1,600 2018-06-13
Debian Linux HIGH 8.8
CVE-2018-12264

Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.…

No fix yet
Fix from $1,950 2018-06-13
Debian Linux HIGH 8.8
CVE-2018-12265

Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.

No fix yet
Fix from $1,950 2018-06-13
Android MEDIUM 5.5
CVE-2018-3579

In the WLAN driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, event->num_entries_in_…

Patch available
Fix from $1,600 2018-06-12
Mruby HIGH 7.5
CVE-2018-12248

An issue was discovered in mruby 1.4.1. There is a heap-based buffer over-read associated with OP_ENTER because mrbgems/mruby-fiber/src/fiber.c does …

Patch available
Fix from $1,950 2018-06-12
Firefox HIGH 7.5
CVE-2018-5153

If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read …

Fix: 60.0+
Fix from $1,950 2018-06-11
Firefox HIGH 8.2
CVE-2017-7813

Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually resu…

Fix: after 55.0.3
Fix from $1,950 2018-06-11
Enterprise Linux Desktop CRITICAL 9.1
CVE-2017-7758

An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vu…

Fix: 52.2.0 / 54.0+
Fix from $2,300 2018-06-11
Firefox CRITICAL 9.8
CVE-2017-7778

A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninit…

Fix: 1.3.10 / 52.2.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.1
CVE-2017-5465EPSS 13%

An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory bein…

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.1
CVE-2017-7753

An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects …

Fix: 52.3.0 / 55.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-7754

An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefo…

Fix: 52.2.0 / 54.0+
Fix from $1,950 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5446

An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable…

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-5418

An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of ran…

Fix: 52.0+
Fix from $1,600 2018-06-11
Tinyexr CRITICAL 9.8
CVE-2018-12092

tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.

Mitigation only
Fix from $2,300 2018-06-11
Ubuntu Linux MEDIUM 6.5
CVE-2018-10360

The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and applic…

Patch available
Fix from $1,600 2018-06-11
Mac Os X MEDIUM 5.5
CVE-2018-4253

An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "AMD" component. It allows local users to…

Fix: 10.13.5+
Fix from $1,600 2018-06-08
Safari HIGH 8.8
CVE-2018-4222EPSS 12%

An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is aff…

Fix: 4.3.1 / 7.5+
Fix from $1,950 2018-06-08
Tinyexr CRITICAL 9.8
CVE-2018-12064

tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.

Mitigation only
Fix from $2,300 2018-06-08
Https Proxy Agent CRITICAL 9.1
CVE-2018-3739

https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory le…

Fix: 2.2.0+
Fix from $2,300 2018-06-07
The Sleuth Kit HIGH 8.1
CVE-2018-11737

An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found…

Fix: after 4.6.1
Fix from $1,950 2018-06-05
The Sleuth Kit HIGH 8.1
CVE-2018-11738

An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found…

Fix: after 4.6.1
Fix from $1,950 2018-06-05
The Sleuth Kit HIGH 8.1
CVE-2018-11739

An issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was foun…

Fix: after 4.6.1
Fix from $1,950 2018-06-05
The Sleuth Kit HIGH 8.1
CVE-2018-11740

An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was fou…

Fix: after 4.6.1
Fix from $1,950 2018-06-05
Libsass HIGH 8.1
CVE-2018-11693

An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::skip_over_scopes…

Fix: after 3.5.4
Fix from $1,950 2018-06-04
Libsass HIGH 8.1
CVE-2018-11697

An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::Prelexer::exactly() which …

Fix: after 3.5.4
Fix from $1,950 2018-06-04
Libsass HIGH 8.1
CVE-2018-11698

An issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::handle_error which could b…

Fix: after 3.5.4
Fix from $1,950 2018-06-04
Xltek Neuroworks HIGH 7.5
CVE-2017-2852

An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted …

Mitigation only
Fix from $1,950 2018-06-01
Xltek Neuroworks HIGH 7.5
CVE-2017-2858

An exploitable denial-of-service vulnerability exists in the traversal of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted networ…

Mitigation only
Fix from $1,950 2018-06-01
Xltek Neuroworks HIGH 7.5
CVE-2017-2860

An exploitable denial-of-service vulnerability exists in the lookup entry functionality of KeyTrees in Natus Xltek NeuroWorks 8. A specially crafted …

Mitigation only
Fix from $1,950 2018-06-01