Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
HIGH 7.5 CVE-2015-7507 libnsbmp.c in Libnsbmp 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a crafted color table to the (1… Libnsbmp No fix yet Fix from $1,9502020-02-18 MEDIUM 6.5 CVE-2015-7506 The gif_next_LZW function in libnsgif.c in Libnsgif 0.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and app… Libnsgif Mitigation only Fix from $1,6002020-02-18 MEDIUM 5.3 CVE-2020-1830 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC600,… Nip6800 Firmware Mitigation only Fix from $1,6002020-02-18 HIGH 7.5 CVE-2020-1828 Huawei NIP6800 versions V500R001C30, V500R001C60SPC500, and V500R005C00; and Secospace USG6600 and USG9500 versions V500R001C30SPC200, V500R001C30SPC… Nip6800 Firmware Mitigation only Fix from $1,9502020-02-17 HIGH 7.5 CVE-2019-20454 An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF… Fedora 8.2.12 / 9.0.6+ Fix from $1,9502020-02-14 HIGH 7.5 CVE-2020-3755 Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier … Acrobat Dc after 19.021.20061 Fix from $1,9502020-02-13 HIGH 7.5 CVE-2020-3744EPSS 9% Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier … Acrobat Dc after 19.021.20061 Fix from $1,9502020-02-13 HIGH 7.5 CVE-2020-3747 Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier … Acrobat Dc after 19.021.20061 Fix from $1,9502020-02-13 MEDIUM 5.5 CVE-2020-0744 An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an att… Windows 10 Patch available Fix from $1,6002020-02-11 MEDIUM 5.5 CVE-2020-5826 Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.21… Endpoint Protection Mitigation only Fix from $1,6002020-02-11 MEDIUM 6.5 CVE-2020-6405 Out of bounds read in SQLite in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from proces… Chrome 80.0.3987.87+ Fix from $1,6002020-02-11 MEDIUM 6.5 CVE-2020-6395 Out of bounds read in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to obtain potentially sensitive information from pr… Chrome 80.0.3987.87+ Fix from $1,6002020-02-11 CRITICAL 9.1 CVE-2020-7059EPSS 7% When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is pos… PHP 5.19.0 / 7.2.27+ Fix from $2,3002020-02-10 CRITICAL 9.1 CVE-2020-7060EPSS 9% When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it… PHP 5.19.0 / 7.2.27+ Fix from $2,3002020-02-10 HIGH 7.8 CVE-2019-17136EPSS 5% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is r… Phantompdf Mitigation only Fix from $1,9502020-02-08 CRITICAL 9.1 CVE-2019-14057 Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snapdragon Auto, Snapdragon Compu… Apq8009 Firmware Mitigation only Fix from $2,3002020-02-07 CRITICAL 9.1 CVE-2019-14063 Out of bound access due to Invalid inputs to dapm mux settings which results into kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon C… Ipq4019 Firmware Patch available Fix from $2,3002020-02-07 MEDIUM 6.5 CVE-2016-7523 coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file. Imagemagick 6.9.4-0+ Fix from $1,6002020-02-06 MEDIUM 6.5 CVE-2016-7524 coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file. Imagemagick 6.9.4-0+ Fix from $1,6002020-02-06 HIGH 7.5 CVE-2020-3123 A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthentica… Ubuntu Linux Mitigation only Fix from $1,9502020-02-05 CRITICAL 9.1 CVE-2020-6058 An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP reques… Minisnmpd No fix yet Fix from $2,3002020-02-04 CRITICAL 9.8 CVE-2020-5235 There is a potentially exploitable out of memory condition In Nanopb before 0.4.1, 0.3.9.5, and 0.2.9.4. When nanopb is compiled with PB_ENABLE_MALLO… Nanopb 0.2.9.4 / 0.3.9.5+ Fix from $2,3002020-02-04 MEDIUM 6.3 CVE-2019-18567 Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing Kernel memory leaks or denia… Bromium after 4.1.7 Fix from $1,6002020-02-03 CRITICAL 9.8 CVE-2014-2898 wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-o… Wolfssl 2.9.0+ Fix from $2,3002020-01-28 CRITICAL 9.8 CVE-2014-2896 The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact an… Wolfssl 2.9.4+ Fix from $2,3002020-01-28 CRITICAL 9.8 CVE-2014-2897 The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote atta… Wolfssl 2.9.4+ Fix from $2,3002020-01-28 CRITICAL 9.1 CVE-2019-20433 libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 … Aspell 0.60.8+ Fix from $2,3002020-01-27 HIGH 7.5 CVE-2019-20428 In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds read and panic due to the lack of validation for specific fields of p… Lustre 2.12.3+ Fix from $1,9502020-01-27 HIGH 7.5 CVE-2019-20429 In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds read and panic (via a modified lm_bufcount field) due to the lack of … Lustre 2.12.3+ Fix from $1,9502020-01-27 HIGH 8.6 CVE-2019-5124 An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.50005. A specially crafted pixel shader can ca… Atidxx64 Mitigation only Fix from $1,9502020-01-25