Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Espruino MEDIUM 5.5
CVE-2018-11592

Espruino before 1.98 allows attackers to cause a denial of service (application crash) with a user crafted input file via an Out-of-bounds Read durin…

Fix: 1.98+
Fix from $1,600 2018-05-31
Espruino HIGH 7.1
CVE-2018-11598

Espruino before 1.99 allows attackers to cause a denial of service (application crash) and a potential Information Disclosure with user crafted input…

Fix: 1.99+
Fix from $1,950 2018-05-31
Ubuntu Linux HIGH 8.8
CVE-2018-11625

In ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a crafted file.

Patch available
Fix from $1,950 2018-05-31
Ngiflib CRITICAL 9.8
CVE-2018-11576

ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor.

Mitigation only
Fix from $2,300 2018-05-31
Libmobi MEDIUM 6.5
CVE-2018-11432

The mobi_parse_mobiheader function in read.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via…

No fix yet
Fix from $1,600 2018-05-30
Libmobi MEDIUM 6.5
CVE-2018-11433

The mobi_get_kf8boundary_seqnumber function in util.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-…

No fix yet
Fix from $1,600 2018-05-30
Libmobi MEDIUM 6.5
CVE-2018-11434

The buffer_fill64 function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via …

No fix yet
Fix from $1,600 2018-05-30
Libmobi MEDIUM 6.5
CVE-2018-11436

The buffer_addraw function in buffer.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a cra…

No fix yet
Fix from $1,600 2018-05-30
Debian Linux MEDIUM 6.5
CVE-2018-11439

The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based bu…

No fix yet
Fix from $1,600 2018-05-30
Ubuntu Linux HIGH 7.5
CVE-2018-11233

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on N…

Fix: after 2.16.3
Fix from $1,950 2018-05-30
Md4c CRITICAL 9.8
CVE-2018-11546

md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error.

Mitigation only
Fix from $2,300 2018-05-29
Md4c CRITICAL 9.8
CVE-2018-11547

md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandles loop termination.

Mitigation only
Fix from $2,300 2018-05-29
Atob CRITICAL 9.1
CVE-2018-3745

atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.

Fix: after 2.0.3
Fix from $2,300 2018-05-29
Debian Linux MEDIUM 5.5
CVE-2018-11503

The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer ove…

Mitigation only
Fix from $1,600 2018-05-26
Debian Linux MEDIUM 5.5
CVE-2018-11504

The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-re…

Mitigation only
Fix from $1,600 2018-05-26
Antivirus\+ MEDIUM 5.5
CVE-2018-6234

An Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to disclose s…

Fix: after 12.0
Fix from $1,600 2018-05-25
Debian Linux MEDIUM 5.5
CVE-2018-11468

The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer o…

No fix yet
Fix from $1,600 2018-05-25
Phantompdf HIGH 8.8
CVE-2018-5677

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1…

Fix: after 9.0.1.1049
Fix from $1,950 2018-05-24
Phantompdf HIGH 8.8
CVE-2018-5679

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1…

Fix: after 9.0.1.1049
Fix from $1,950 2018-05-24
Phantompdf HIGH 8.8
CVE-2018-5680

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1…

Fix: after 9.0.1.1049
Fix from $1,950 2018-05-24
Jerryscript CRITICAL 9.8
CVE-2018-11418

An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_utf8 function via a RegExp("[\\u002…

No fix yet
Fix from $2,300 2018-05-24
Jerryscript CRITICAL 9.8
CVE-2018-11419

An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex function via a RegExp("[\\u0") …

No fix yet
Fix from $2,300 2018-05-24
Debian Linux CRITICAL 9.1
CVE-2018-1000301EPSS 6%

curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl…

Fix: 7.2+
Fix from $2,300 2018-05-24
Wireshark HIGH 7.5
CVE-2018-11362

In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoid…

Fix: after 2.4.6
Fix from $1,950 2018-05-22
Radare2 MEDIUM 5.5
CVE-2018-11375

The _inst__lds() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash)…

Patch available
Fix from $1,600 2018-05-22
Radare2 MEDIUM 5.5
CVE-2018-11376

The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash…

Patch available
Fix from $1,600 2018-05-22
Radare2 MEDIUM 5.5
CVE-2018-11377

The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application cr…

Patch available
Fix from $1,600 2018-05-22
Radare2 MEDIUM 5.5
CVE-2018-11379

The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application cr…

Patch available
Fix from $1,600 2018-05-22
Radare2 MEDIUM 5.5
CVE-2018-11380

The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application …

Patch available
Fix from $1,600 2018-05-22
Radare2 MEDIUM 5.5
CVE-2018-11381

The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application…

Patch available
Fix from $1,600 2018-05-22