Vulnerability index

Browse CVEs

3,271 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
High Resolution Streaming Image Server HIGH 7.5
CVE-2021-46389

IIPImage High Resolution Streaming Image Server prior to commit 882925b295a80ec992063deffc2a3b0d803c3195 is affected by an integer overflow in iipsrv…

Fix: 2022-01-14+
Fix from $1,950 2022-02-07
Cgi CRITICAL 9.8
CVE-2021-41816

CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such …

Fix: 0.3.1+
Fix from $2,300 2022-02-06
Tensorflow CRITICAL 9.8
CVE-2022-23587

Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow is vulnerable to an integer overfl…

Fix: after 2.6.2
Fix from $2,300 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23575

Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateTensorSize` is vulnerable to an intege…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-23576

Tensorflow is an Open Source Machine Learning Framework. The implementation of `OpLevelCostEstimator::CalculateOutputSize` is vulnerable to an intege…

Fix: after 2.6.2
Fix from $1,600 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-23558

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in `TfLiteIntArray…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-23559

Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an integer overflow in embedding looku…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow HIGH 8.8
CVE-2022-23562

Tensorflow is an Open Source Machine Learning Framework. The implementation of `Range` suffers from integer overflows. These can trigger undefined be…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
Tensorflow MEDIUM 6.5
CVE-2022-21738

Tensorflow is an Open Source Machine Learning Framework. The implementation of `SparseCountSparseOutput` can be made to crash a TensorFlow process by…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21729

Tensorflow is an Open Source Machine Learning Framework. The implementation of `UnravelIndex` is vulnerable to a division by zero caused by an intege…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-23567

Tensorflow is an Open Source Machine Learning Framework. The implementations of `Sparse*Cwise*` ops are vulnerable to integer overflows. These can be…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-23568

Tensorflow is an Open Source Machine Learning Framework. The implementation of `AddManySparseToTensorsMap` is vulnerable to an integer overflow which…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow MEDIUM 6.5
CVE-2022-21733

Tensorflow is an Open Source Machine Learning Framework. The implementation of `StringNGrams` can be used to trigger a denial of service attack by ca…

Fix: after 2.6.2
Fix from $1,600 2022-02-03
Tensorflow HIGH 8.8
CVE-2022-21727

Tensorflow is an Open Source Machine Learning Framework. The implementation of shape inference for `Dequantize` is vulnerable to an integer overflow …

Fix: after 2.6.2
Fix from $1,950 2022-02-03
MariaDB MEDIUM 5.5
CVE-2021-46667

MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.

Fix: 10.2.41 / 10.3.32+
Fix from $1,600 2022-02-01
Rlc 410w Firmware HIGH 7.5
CVE-2022-21801

A denial of service vulnerability exists in the netserver recv_command functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted net…

Mitigation only
Fix from $1,950 2022-01-28
Rbpf HIGH 7.5
CVE-2021-46102

From version 0.2.14 to 0.2.16 for Solana rBPF, function "relocate" in the file src/elf.rs has an integer overflow bug because the sym.st_value is rea…

Fix: after 0.2.16
Fix from $1,950 2022-01-27
Debian Linux HIGH 7.5
CVE-2022-23990

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

Fix: 2.4.4 / 3.1+
Fix from $1,950 2022-01-26
Debian Linux CRITICAL 9.8
CVE-2022-23852

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

Fix: 2.4.4 / 3.1+
Fix from $2,300 2022-01-24
Uc\/lib CRITICAL 9.8
CVE-2021-26706

An issue was discovered in lib_mem.c in Micrium uC/OS uC/LIB 1.38.x and 1.39.00. The following memory allocation functions do not check for integer o…

Mitigation only
Fix from $2,300 2022-01-24
Linkit Software Development Kit CRITICAL 9.8
CVE-2021-30636

In MediaTek LinkIt SDK before 4.6.1, there is a possible memory corruption due to an integer overflow during mishandled memory allocation by pvPortCa…

Fix: 4.6.1+
Fix from $2,300 2022-01-24
Android Q Sdk HIGH 7.5
CVE-2021-38787

There is an integer overflow in the ION driver "/dev/ion" of Allwinner R818 SoC Android Q SDK V1.0 that could use the ioctl cmd "COMPAT_ION_IOC_SUNXI…

Mitigation only
Fix from $1,950 2022-01-19
Acrobat Dc HIGH 7.8
CVE-2021-44711EPSS 10%

Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Integer Overflow o…

Fix: after 21.007.20099
Fix from $1,950 2022-01-14
Apq8009 Firmware HIGH 7.8
CVE-2021-30319

Possible integer overflow due to improper validation of command length parameters while processing WMI command in Snapdragon Auto, Snapdragon Compute…

Patch available
Fix from $1,950 2022-01-13
Fedora HIGH 8.6
CVE-2022-21668

pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requiremen…

Fix: 2022.1.8+
Fix from $1,950 2022-01-10
Debian Linux HIGH 8.8
CVE-2022-22826

nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $1,950 2022-01-10
Debian Linux HIGH 8.8
CVE-2022-22827

storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $1,950 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2022-22822

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2022-22823

build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2022-22824

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10