Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2018-12827EPSS 32%
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Enterprise Linux Desktop
after 30.0.0.154
MEDIUM 5.9
CVE-2018-12824EPSS 11%
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
Enterprise Linux Desktop
after 30.0.0.154
MEDIUM 5.5
CVE-2018-16062
dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer…
Debian Linux
0.174+
HIGH 7.5
CVE-2018-15501
In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packe…
Debian Linux
0.26.6 / 0.27.4+
HIGH 7.8
CVE-2018-15471
An issue was discovered in xenvif_set_hash_mapping in drivers/net/xen-netback/hash.c in the Linux kernel through 4.18.1, as used in Xen through 4.11.…
Linux Kernel
4.9.133 / 4.14.76+
MEDIUM 6.5
CVE-2016-9598
libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of-bounds read and application …
Jboss Core Services
2.9.4+
HIGH 7.5
CVE-2018-0409
A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Vi…
Telepresence Video Communication Server
Mitigation only
MEDIUM 5.5
CVE-2018-8378EPSS 8%
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could…
Excel Viewer
Patch available
MEDIUM 6.5
CVE-2018-6970
VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1) contain an out-of-bounds rea…
Horizon Client
4.8.1 / 6.2.7+
HIGH 8.1
CVE-2018-10598
CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cause the software to crash due …
Cncsoft
after 1.00.83
CRITICAL 9.1
CVE-2018-14938
An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during cap…
Ubuntu Linux
after 1.4.5
HIGH 7.5
CVE-2018-14883EPSS 9%
An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-b…
PHP
5.6.37 / 7.0.31+
MEDIUM 5.5
CVE-2018-14851
exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote…
PHP
7.0.31 / 7.1.20+
HIGH 7.5
CVE-2017-9118
PHP 7.1.5 has an Out of bounds access in php_pcre_replace_impl via a crafted preg_replace call.
PHP
7.4.27 / 8.0.14+
HIGH 7.8
CVE-2016-9583
An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.
Enterprise Linux Desktop
2.0.6+
MEDIUM 5.5
CVE-2017-5692
Out-of-bounds read condition in older versions of some Intel Graphics Driver for Windows code branches allows local users to perform a denial of serv…
Graphics Driver
Mitigation only
CRITICAL 9.8
CVE-2016-8620
The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.
Curl
7.51.0+
HIGH 8.1
CVE-2016-9573
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another fo…
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2016-8621EPSS 5%
The `curl_getdate` function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input with one digit short.
Curl
7.51.0+
MEDIUM 6.5
CVE-2018-14316
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction…
Foxit Reader
after 9.1.0.5096
MEDIUM 6.5
CVE-2018-14289
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction…
Foxit Reader
after 9.1.0.5096
MEDIUM 6.5
CVE-2018-11620
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction…
Foxit Reader
after 9.1.0.5096
MEDIUM 6.5
CVE-2018-11621
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction…
Foxit Reader
after 9.1.0.5096
HIGH 7.5
CVE-2018-14736
An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A buffer over-read can occur in pbc_wmessage_string in wmessage.c for PTYPE_EN…
Pbc
after 2017-03-02
CRITICAL 9.9
CVE-2017-2620
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could…
Xenserver
Patch available
MEDIUM 6.5
CVE-2017-2633
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshin…
Enterprise Linux Desktop
1.7.2+
HIGH 7.8
CVE-2018-1056
An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potenti…
Ubuntu Linux
2.1+
HIGH 7.8
CVE-2017-2579
An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so tha…
Netpbm
Mitigation only
MEDIUM 5.5
CVE-2018-14610
An issue was discovered in the Linux kernel through 4.17.10. There is out-of-bounds access in write_extent_buffer() when mounting and operating a cra…
Linux Kernel
after 4.17.10
MEDIUM 5.5
CVE-2017-18344
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev…
Linux Kernel
4.14.8+