Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Libopenmpt MEDIUM 6.5
CVE-2018-10017

soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial of service (out-of-bounds read…

Fix: 0.3.8 / 1.27.07.00+
Fix from $1,600 2018-04-11
Debian Linux MEDIUM 6.5
CVE-2018-10001

The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) …

Fix: after 3.4.2
Fix from $1,600 2018-04-11
Debian Linux MEDIUM 5.5
CVE-2018-3837

An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A s…

No fix yet
Fix from $1,600 2018-04-10
Debian Linux MEDIUM 6.5
CVE-2018-3838

An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially cr…

No fix yet
Fix from $1,600 2018-04-10
Debian Linux HIGH 7.5
CVE-2018-9988

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on inva…

Fix: 2.1.11 / 2.7.2+
Fix from $1,950 2018-04-10
Debian Linux HIGH 7.5
CVE-2018-9989

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid …

Fix: 2.1.11 / 2.7.2+
Fix from $1,950 2018-04-10
Ffmpeg HIGH 8.8
CVE-2018-9841

The export function in libavfilter/vf_signature.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out-of-array access) …

Fix: after 3.4.2
Fix from $1,950 2018-04-07
Xltek Neuroworks HIGH 7.5
CVE-2017-2861

An exploitable Denial of Service vulnerability exists in the use of a return value in the NewProducerStream command in Natus Xltek NeuroWorks 8. A sp…

Mitigation only
Fix from $1,950 2018-04-05
Exiv2 HIGH 8.1
CVE-2018-9305

In Exiv2 0.26, an out-of-bounds read in IptcData::printStructure in iptc.c could result in a crash or information leak, related to the "== 0x1c" case.

Fix: 0.26+
Fix from $1,950 2018-04-04
Android MEDIUM 6.5
CVE-2017-13262EPSS 7%

In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. This could lead to remote infor…

No fix yet
Fix from $1,600 2018-04-04
Android HIGH 7.5
CVE-2017-13258EPSS 6%

In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclos…

No fix yet
Fix from $1,950 2018-04-04
Android HIGH 7.5
CVE-2017-13259

In functionality implemented in sdp_discovery.cc, there are possible out of bounds reads due to missing bounds checks. This could lead to remote info…

Mitigation only
Fix from $1,950 2018-04-04
Android HIGH 7.5
CVE-2017-13260EPSS 6%

In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclos…

No fix yet
Fix from $1,950 2018-04-04
Android HIGH 7.5
CVE-2017-13261EPSS 6%

In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote info…

No fix yet
Fix from $1,950 2018-04-04
Android MEDIUM 6.2
CVE-2017-13290

In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check. This could lead to local information …

Mitigation only
Fix from $1,600 2018-04-04
Ubuntu Linux HIGH 7.1
CVE-2017-13305

A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.

No fix yet
Fix from $1,950 2018-04-04
Android MEDIUM 5.5
CVE-2017-13275

In getVSCoverage of CmapCoverage.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information d…

Mitigation only
Fix from $1,600 2018-04-04
Android HIGH 7.5
CVE-2017-13280

In the FrameSequence_gif::FrameSequence_gif function of libframesequence, there is a out of bounds read due to a missing bounds check. This could lea…

Mitigation only
Fix from $1,950 2018-04-04
Android HIGH 7.3
CVE-2018-5821

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch leve…

Mitigation only
Fix from $1,950 2018-04-03
Android MEDIUM 5.3
CVE-2017-15837

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch leve…

Mitigation only
Fix from $1,600 2018-04-03
Android MEDIUM 5.3
CVE-2017-15853

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch leve…

Mitigation only
Fix from $1,600 2018-04-03
Mac Os X HIGH 7.8
CVE-2018-4160

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers t…

Fix: 10.13.4+
Fix from $1,950 2018-04-03
Mac Os X HIGH 7.8
CVE-2018-4136

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Kernel" component. It allows attackers t…

Fix: 10.13.4+
Fix from $1,950 2018-04-03
Gpu Driver HIGH 8.8
CVE-2018-6248

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape where the software uses a sequential op…

Mitigation only
Fix from $1,950 2018-04-02
Linux Kernel MEDIUM 5.5
CVE-2018-1093

The ext4_valid_block_bitmap function in fs/ext4/balloc.c in the Linux kernel through 4.15.15 allows attackers to cause a denial of service (out-of-bo…

Fix: after 4.15.15
Fix from $1,600 2018-04-02
Imagemagick HIGH 8.8
CVE-2018-9135

In ImageMagick 7.0.7-24 Q16, there is a heap-based buffer over-read in IsWEBPImageLossless in coders/webp.c.

No fix yet
Fix from $1,950 2018-03-30
Exiv2 HIGH 8.1
CVE-2018-9144

In Exiv2 0.26, there is an out-of-bounds read in Exiv2::Internal::binaryToString in image.cpp. It could result in denial of service or information di…

Fix: 0.26+
Fix from $1,950 2018-03-30
Ubuntu Linux MEDIUM 5.5
CVE-2018-0202EPSS 5%

clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) con…

Fix: after 0.99.3
Fix from $1,600 2018-03-27
HTTP Server HIGH 7.5
CVE-2018-1303EPSS 65%

A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing…

Fix: after 2.4.29
Fix from $1,950 2018-03-26
Netpbm MEDIUM 5.5
CVE-2018-8975

The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buff…

Fix: after 10.81.03
Fix from $1,600 2018-03-25