Vulnerability index

Browse CVEs

3,271 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Jetson Linux MEDIUM 5.0
CVE-2022-28197

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_mount function, where Insufficient validation of untrusted data may all…

Fix: 32.7.2+
Fix from $1,600 2022-04-27
Debian Linux HIGH 7.8
CVE-2021-3624

There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be exe…

No fix yet
Fix from $1,950 2022-04-18
Bimx Desktop Viewer HIGH 7.8
CVE-2020-6099

An exploitable code execution vulnerability exists in the file format parsing functionality of Graphisoft BIMx Desktop Viewer 2019.2.2328. A speciall…

No fix yet
Fix from $1,950 2022-04-18
Ios Xe MEDIUM 6.5
CVE-2022-20684

A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of Cisco IOS XE Wireless Controller Software for th…

Mitigation only
Fix from $1,600 2022-04-15
Fedora MEDIUM 6.5
CVE-2022-28041

stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers…

Patch available
Fix from $1,600 2022-04-15
Leadtools HIGH 7.8
CVE-2022-21154

An integer overflow vulnerability exists in the fltSaveCMP functionality of Leadtools 22. A specially-crafted BMP file can lead to an integer overflo…

No fix yet
Fix from $1,950 2022-04-14
Imagegear HIGH 8.8
CVE-2021-21914

A heap-based buffer overflow vulnerability exists in the DecoderStream::Append functionality of Accusoft ImageGear 19.10. A specially-crafted file ca…

No fix yet
Fix from $1,950 2022-04-14
Chitubox Basic HIGH 7.8
CVE-2021-21948

A heap-based buffer overflow vulnerability exists in the readDatHeadVec functionality of AnyCubic Chitubox AnyCubic Plugin 1.0.0. A specially-crafted…

No fix yet
Fix from $1,950 2022-04-14
Vyper CRITICAL 9.8
CVE-2022-24845

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In affected versions, the return of `<iface>.returns_int128()` is not v…

Fix: 0.3.2+
Fix from $2,300 2022-04-13
Android HIGH 7.8
CVE-2022-27833

Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.

Mitigation only
Fix from $1,950 2022-04-11
Android MEDIUM 6.7
CVE-2022-20075

In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution pr…

Mitigation only
Fix from $1,600 2022-04-11
Android MEDIUM 6.6
CVE-2022-20069

In preloader (usb), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege, for an atta…

Mitigation only
Fix from $1,600 2022-04-11
Gpac MEDIUM 5.5
CVE-2022-27148

GPAC mp4box 1.1.0-DEV-rev1663-g881c6a94a-master is vulnerable to Integer Overflow.

Fix: 2.0.0+
Fix from $1,600 2022-04-08
Yajl Ruby HIGH 7.5
CVE-2022-24795

yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow whi…

Fix: 1.4.2+
Fix from $1,950 2022-04-05
Chrome HIGH 8.8
CVE-2022-0608

Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Fix: 98.0.4758.102+
Fix from $1,950 2022-04-05
Linux Kernel HIGH 7.8
CVE-2022-0998

An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function…

Fix: 5.10.88 / 5.15.11+
Fix from $1,950 2022-03-30
Android HIGH 7.8
CVE-2021-39759

In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no addit…

Mitigation only
Fix from $1,950 2022-03-30
Android HIGH 7.5
CVE-2021-39762

In tremolo, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional ex…

No fix yet
Fix from $1,950 2022-03-30
Cuda Toolkit HIGH 7.8
CVE-2022-21821

NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a loca…

Fix: 11.6.2+
Fix from $1,950 2022-03-29
Bedrock Server CRITICAL 9.8
CVE-2022-23884

Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (pac…

No fix yet
Fix from $2,300 2022-03-28
Fedora MEDIUM 5.5
CVE-2021-3933

An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and…

Fix: 3.1.2+
Fix from $1,600 2022-03-25
Microweber HIGH 7.5
CVE-2022-1036

Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.

Fix: 1.2.12+
Fix from $1,950 2022-03-22
Android HIGH 7.8
CVE-2021-39732

In copy_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privil…

Mitigation only
Fix from $1,950 2022-03-16
Android MEDIUM 6.7
CVE-2021-39736

In prepare_io_entry and prepare_response of lwis_ioctl.c and lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. …

Mitigation only
Fix from $1,600 2022-03-16
Android HIGH 7.8
CVE-2021-39714

In ion_buffer_kmap_get of ion.c, there is a possible use-after-free due to an integer overflow. This could lead to local escalation of privilege with…

Patch available
Fix from $1,950 2022-03-16
Android MEDIUM 6.7
CVE-2021-39719

In lwis_top_register_io of lwis_device_top.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation…

Mitigation only
Fix from $1,600 2022-03-16
Microweber MEDIUM 5.5
CVE-2022-0968

The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Ser…

Fix: 1.2.12+
Fix from $1,600 2022-03-15
Microweber MEDIUM 5.5
CVE-2022-0961

The microweber application allows large characters to insert in the input field "post title" which can allow attackers to cause a Denial of Service (…

Fix: 1.2.12+
Fix from $1,600 2022-03-15
HTTP Server CRITICAL 9.1
CVE-2022-22721EPSS 42%

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later ca…

Fix: 10.15.7 / 11.6.6+
Fix from $2,300 2022-03-14
HTTP Server CRITICAL 9.8
CVE-2022-23943EPSS 50%

Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. …

Fix: 2.4.53+
Fix from $2,300 2022-03-14