Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
MEDIUM 6.5 CVE-2018-20536 There is a heap-based buffer over-read at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that will cause a denial of serv… Liblas No fix yet Fix from $1,6002018-12-28 MEDIUM 5.5 CVE-2018-20456 In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application cra… Radare2 3.1.1+ Fix from $1,6002018-12-25 MEDIUM 5.5 CVE-2018-20457 In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via a… Radare2 after 3.1.3 Fix from $1,6002018-12-25 MEDIUM 5.5 CVE-2018-20458 In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a denial-of-service (application… Radare2 3.1.1+ Fix from $1,6002018-12-25 MEDIUM 5.5 CVE-2018-20459 In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash… Radare2 after 3.1.3 Fix from $1,6002018-12-25 MEDIUM 5.5 CVE-2018-20461 In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (application crash caused by out-of-… Radare2 3.1.1+ Fix from $1,6002018-12-25 MEDIUM 6.5 CVE-2018-20451 The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of servi… Libdoc after 2017-10-23 Fix from $1,6002018-12-25 MEDIUM 6.5 CVE-2018-20453 The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service … Libdoc after 20171023 Fix from $1,6002018-12-25 MEDIUM 6.5 CVE-2018-20430 GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRAC… Debian Linux after 1.8 Fix from $1,6002018-12-24 MEDIUM 6.5 CVE-2018-20409 An issue was discovered in Bento4 1.5.1-627. There is a heap-based buffer over-read in AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp, as demonstrated … Bento4 No fix yet Fix from $1,6002018-12-23 MEDIUM 5.5 CVE-2018-20124 hw/rdma/rdma_backend.c in QEMU allows guest OS users to trigger out-of-bounds access via a PvrdmaSqWqe ring element with a large num_sge value. Ubuntu Linux after 3.1.0 Fix from $1,6002018-12-20 MEDIUM 6.5 CVE-2018-1000852 FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/… Ubuntu Linux 2.0.0+ Fix from $1,6002018-12-20 HIGH 7.8 CVE-2018-11963 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Buffer overread may occur due to non-null … Android Patch available Fix from $1,9502018-12-20 HIGH 7.8 CVE-2018-20201 There is a stack-based buffer over-read in the jsfNameFromString function of jsflash.c in Espruino 2V00, leading to a denial of service or possibly u… Espruino No fix yet Fix from $1,9502018-12-18 MEDIUM 5.3 CVE-2018-20185 In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which a… Debian Linux Patch available Fix from $1,6002018-12-17 MEDIUM 5.5 CVE-2018-19975 In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in libyara/exec.c. Specifically, OP_… Yara No fix yet Fix from $1,6002018-12-17 HIGH 7.5 CVE-2018-20102 An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS resp… Ubuntu Linux after 1.8.14 Fix from $1,9502018-12-12 HIGH 7.8 CVE-2018-11465 A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4… Sinumerik 808d V4.7 Firmware after 4.8 Fix from $1,9502018-12-12 MEDIUM 6.5 CVE-2018-20096 There is a heap-based buffer over-read in the Exiv2::tEXtToDataBuf function of pngimage.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote … Exiv2 Patch available Fix from $1,6002018-12-12 MEDIUM 6.5 CVE-2018-20098 There is a heap-based buffer over-read in Exiv2::Jp2Image::encodeJp2Header of jp2image.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote d… Exiv2 Patch available Fix from $1,6002018-12-12 HIGH 8.8 CVE-2018-18359 Incorrect handling of Reflect.construct in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to perform an out of bounds memory rea… Chrome 71.0.3578.80+ Fix from $1,9502018-12-11 MEDIUM 6.5 CVE-2018-5811 An error within the "nikon_coolscan_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an … Ubuntu Linux 0.18.9+ Fix from $1,6002018-12-07 MEDIUM 6.5 CVE-2017-16910 An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause … Ubuntu Linux 0.18.6+ Fix from $1,6002018-12-07 HIGH 8.8 CVE-2018-5802 An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can… Enterprise Linux Desktop 0.18.7+ Fix from $1,9502018-12-07 HIGH 8.8 CVE-2018-5807 An error within the "samsung_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause an out-of-… Ubuntu Linux 0.18.9+ Fix from $1,9502018-12-07 CRITICAL 9.1 CVE-2018-18313EPSS 10% Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory. Perl 5.26.3+ Fix from $2,3002018-12-07 HIGH 7.5 CVE-2018-9562 In bta_ag_do_disc of bta_ag_sdp.cc, there is a possible out-of-bound read due to an incorrect parameter size. This could lead to remote information d… Android Mitigation only Fix from $1,9502018-12-06 HIGH 7.5 CVE-2018-9565 In readBytes of xltdecwbxml.c, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure wi… Android Mitigation only Fix from $1,9502018-12-06 MEDIUM 5.7 CVE-2018-9566 In process_service_search_rsp of sdp_discovery.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote inf… Android Mitigation only Fix from $1,6002018-12-06 HIGH 7.8 CVE-2018-9538 In V4L2SliceVideoDecodeAccelerator::Dequeue of v4l2_slice_video_decode_accelerator.cc, there is a possible out of bounds read of a function pointer d… Android Patch available Fix from $1,9502018-12-06