Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
HIGH 7.8 CVE-2018-19504 An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There is a NULL pointer dereference in ifilter_bank() in libfaad/filtbank… Freeware Advanced Audio Decoder 2 No fix yet Fix from $1,9502018-11-23 HIGH 7.8 CVE-2018-19416 An issue was discovered in sysstat 12.1.1. The remap_struct function in sa_common.c has an out-of-bounds read during a memmove call, as demonstrated … Sysstat No fix yet Fix from $1,9502018-11-21 MEDIUM 5.5 CVE-2018-19388 FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read, access violation, and applicati… Foxit Reader No fix yet Fix from $1,6002018-11-20 MEDIUM 5.5 CVE-2018-19389 FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Break instruction exception and application crash) … Foxit Reader No fix yet Fix from $1,6002018-11-20 MEDIUM 5.5 CVE-2018-19390 FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (Break instruction exception and application crash) … Foxit Reader No fix yet Fix from $1,6002018-11-20 MEDIUM 6.5 CVE-2018-19353 The ansilove_ansi function in loaders/ansi.c in libansilove 1.0.0 allows remote attackers to cause a denial of service (out-of-bounds read and applic… Libansilove No fix yet Fix from $1,6002018-11-18 HIGH 7.1 CVE-2018-19341 The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s… Foxit Reader Mitigation only Fix from $1,9502018-11-17 HIGH 7.1 CVE-2018-19342 The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s… Foxit Reader Mitigation only Fix from $1,9502018-11-17 HIGH 7.1 CVE-2018-19343 The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s… Foxit Reader Mitigation only Fix from $1,9502018-11-17 HIGH 7.1 CVE-2018-19344 The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s… Foxit Reader Mitigation only Fix from $1,9502018-11-17 HIGH 7.1 CVE-2018-19345 The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s… Foxit Reader Mitigation only Fix from $1,9502018-11-17 HIGH 7.1 CVE-2018-19346 The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s… Foxit Reader Mitigation only Fix from $1,9502018-11-17 HIGH 7.1 CVE-2018-19347 The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s… Foxit Reader Mitigation only Fix from $1,9502018-11-17 HIGH 7.1 CVE-2018-19348 The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of s… Foxit Reader Mitigation only Fix from $1,9502018-11-17 MEDIUM 5.5 CVE-2018-18954 The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory. Ubuntu Linux 3.1+ Fix from $1,6002018-11-15 MEDIUM 6.5 CVE-2015-9274 HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB… Harfbuzz 1.0.4+ Fix from $1,6002018-11-15 HIGH 7.5 CVE-2018-9541 In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote informati… Android Patch available Fix from $1,9502018-11-14 HIGH 7.5 CVE-2018-9542 In avrc_pars_vendor_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informati… Android Patch available Fix from $1,9502018-11-14 MEDIUM 5.5 CVE-2018-9544 In register_app of btif_hd.cc, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure … Android Patch available Fix from $1,6002018-11-14 HIGH 7.5 CVE-2018-9540 In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote infor… Android Patch available Fix from $1,9502018-11-14 HIGH 8.8 CVE-2018-6067 Incorrect IPC serialization in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a cr… Chrome 65.0.3325.146+ Fix from $1,9502018-11-14 MEDIUM 6.5 CVE-2018-6069 Stack buffer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted… Chrome 65.0.3325.146+ Fix from $1,6002018-11-14 HIGH 8.8 CVE-2018-6071 An integer overflow in Skia in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform an out of bounds memory read via a crafted H… Chrome 65.0.3325.146+ Fix from $1,9502018-11-14 HIGH 8.8 CVE-2018-17466 Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a cr… Chrome 70.0.3538.67+ Fix from $1,9502018-11-14 HIGH 8.8 CVE-2018-17469 Incorrect handling of PDF filter chains in PDFium in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory… Chrome 70.0.3538.67+ Fix from $1,9502018-11-14 HIGH 7.8 CVE-2018-19214 Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input. Enterprise Linux Patch available Fix from $1,9502018-11-12 HIGH 7.8 CVE-2018-19215 Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and !… Enterprise Linux No fix yet Fix from $1,9502018-11-12 MEDIUM 6.5 CVE-2018-19218 In LibSass 3.5-stable, there is an illegal address access at Sass::Parser::parse_css_variable_value_token that will lead to a DoS attack. Libsass No fix yet Fix from $1,6002018-11-12 MEDIUM 6.5 CVE-2018-19128 In Libav 12.3, there is a heap-based buffer over-read in decode_frame in libavcodec/lcldec.c that allows an attacker to cause denial-of-service via a… Libav Mitigation only Fix from $1,6002018-11-09 MEDIUM 6.5 CVE-2018-19107 In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-bas… Debian Linux Patch available Fix from $1,6002018-11-08