Vulnerability index

Browse CVEs

3,271 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Tensorflow MEDIUM 5.5
CVE-2022-29203

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.Space…

Fix: 2.6.4 / 2.7.2+
Fix from $1,600 2022-05-20
Jt2go MEDIUM 5.5
CVE-2022-29030

A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visual…

Fix: 13.3.0.3 / 14.0.0.1+
Fix from $1,600 2022-05-20
Trudesk MEDIUM 6.5
CVE-2022-1754

Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2.

Fix: 1.2.2+
Fix from $1,600 2022-05-20
Spring Security MEDIUM 5.3
CVE-2022-22976

Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When…

Fix: 5.5.7 / 5.6.4+
Fix from $1,600 2022-05-19
Linux Kernel HIGH 7.8
CVE-2022-1116

Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to …

Fix: 5.4.189+
Fix from $1,950 2022-05-17
Trudesk MEDIUM 6.5
CVE-2022-1728

Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be a…

Fix: 1.2.2+
Fix from $1,600 2022-05-16
Fisco Bcos HIGH 7.5
CVE-2022-28936

FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow and cause a Denial of Service …

Mitigation only
Fix from $1,950 2022-05-15
Fisco Bcos HIGH 7.5
CVE-2022-28937

FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an invalid header, will cause no…

No fix yet
Fix from $1,950 2022-05-15
Organizr HIGH 7.5
CVE-2022-1699

Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack fo…

Fix: 2.1.2000+
Fix from $1,950 2022-05-12
Debian Linux MEDIUM 5.5
CVE-2022-27114

There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large …

Patch available
Fix from $1,600 2022-05-09
Eufy Homebase 2 Firmware MEDIUM 6.5
CVE-2022-26073

A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set…

No fix yet
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-28705

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13…

Mitigation only
Fix from $1,950 2022-05-05
Ffjpeg MEDIUM 6.5
CVE-2022-28471

In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap o…

No fix yet
Fix from $1,600 2022-05-05
Android HIGH 7.8
CVE-2022-21743

In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege with no additional execution …

Mitigation only
Fix from $1,950 2022-05-03
Mqx CRITICAL 9.8
CVE-2021-22680

NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignm…

Fix: after 5.1
Fix from $2,300 2022-05-03
Micrium Os MEDIUM 6.5
CVE-2021-27411

Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCreateHW and Mem_PoolCreate. Th…

Fix: after 5.10.1
Fix from $1,600 2022-05-03
Ecospro CRITICAL 9.8
CVE-2021-27417

eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implementation of malloc). The unve…

Fix: after 4.5.3
Fix from $2,300 2022-05-03
Uclibc Ng CRITICAL 9.8
CVE-2021-27419

uClibc-ng versions prior to 1.0.37 are vulnerable to integer wrap-around in functions malloc-simple. This improper memory assignment can lead to arbi…

Fix: 1.0.37+
Fix from $2,300 2022-05-03
Mcuxpresso Software Development Kit CRITICAL 9.8
CVE-2021-27421

NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations ou…

Fix: 2.8.2+
Fix from $2,300 2022-05-03
Mongoose Os CRITICAL 9.8
CVE-2021-27425

Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory assignment can lead to arbitrar…

Mitigation only
Fix from $2,300 2022-05-03
Riot CRITICAL 9.8
CVE-2021-27427

RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead to arbitrary memory allocatio…

Mitigation only
Fix from $2,300 2022-05-03
Cmsis Rtos CRITICAL 9.8
CVE-2021-27431

ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead t…

Fix: after 2.1.3
Fix from $2,300 2022-05-03
Mbed Ualloc CRITICAL 9.8
CVE-2021-27433

ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead to arbitrary memory allocatio…

Patch available
Fix from $2,300 2022-05-03
Mbed CRITICAL 9.8
CVE-2021-27435

ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitrary memory allocation, result…

Patch available
Fix from $2,300 2022-05-03
Tencentos Tiny CRITICAL 9.8
CVE-2021-27439

TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of effective memory allocation …

Mitigation only
Fix from $2,300 2022-05-03
Fuchsia HIGH 7.8
CVE-2021-22556

The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache invalidation operations on pag…

Fix: 4.1+
Fix from $1,950 2022-05-03
Fedora MEDIUM 6.5
CVE-2022-29824

In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can re…

Fix: 2.9.14+
Fix from $1,600 2022-05-03
Ffmpeg MEDIUM 5.5
CVE-2022-1475

An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavcodec/g729_parser.c when proces…

Fix: 4.4.2+
Fix from $1,600 2022-05-02
Enterprise Linux HIGH 8.2
CVE-2021-4206

A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a smal…

Fix: 7.0.0+
Fix from $1,950 2022-04-29
Jetson Linux MEDIUM 5.7
CVE-2022-28195

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may…

Fix: 32.7.2+
Fix from $1,600 2022-04-27