Vulnerability index

Browse CVEs

3,271 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Debian Linux HIGH 7.1
CVE-2018-10195

lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size…

Fix: after 0.12.20
Fix from $1,950 2021-06-02
Lz4 CRITICAL 9.8
CVE-2021-3520

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading t…

Fix: 1.9.4 / 8.2.12+
Fix from $2,300 2021-06-02
Semac S2 Firmware MEDIUM 6.5
CVE-2021-31642EPSS 44%

A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630,…

No fix yet
Fix from $1,600 2021-06-01
PostgreSQL HIGH 8.8
CVE-2021-32027

A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array …

Fix: 9.6.22 / 10.17+
Fix from $1,950 2021-06-01
Debian Linux MEDIUM 6.5
CVE-2021-31808EPSS 5%

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (ag…

Fix: 4.15 / 5.0.6+
Fix from $1,600 2021-05-27
Zephyr HIGH 7.8
CVE-2020-13603

Integer Overflow in memory allocating functions. Zephyr versions >= 1.14.2, >= 2.4.0 contain Integer Overflow or Wraparound (CWE-190). For more infor…

Fix: after 2.2.0
Fix from $1,950 2021-05-25
Envoy HIGH 7.5
CVE-2021-28682

An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to u…

No fix yet
Fix from $1,950 2021-05-20
Telegram MEDIUM 5.5
CVE-2021-31319

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function …

Fix: 7.1.0+
Fix from $1,600 2021-05-18
Fedora CRITICAL 9.1
CVE-2021-3402

An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker to either c…

Fix: 4.0.4+
Fix from $2,300 2021-05-14
Tensorflow HIGH 7.1
CVE-2021-29601

TensorFlow is an end-to-end open source platform for machine learning. The TFLite implementation of concatenation is vulnerable to an integer overflo…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29605

TensorFlow is an end-to-end open source platform for machine learning. The TFLite code for allocating `TFLiteIntArray`s is vulnerable to an integer o…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29584

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in caused by an…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29523

TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger a denial of service via a `CHECK`-fail in `tf.raw_ops.…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Vxworks CRITICAL 9.8
CVE-2020-35198

An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allo…

Fix: 6.9.4.12 / 21.03+
Fix from $2,300 2021-05-12
Debian Linux HIGH 7.5
CVE-2021-20312

A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined beha…

Fix: 7.0.11-0+
Fix from $1,950 2021-05-11
Cc3100 Software Development Kit HIGH 7.8
CVE-2021-22677

An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-service condi…

Fix: 4.10.03 / 4.40.00+
Fix from $1,950 2021-05-07
Cc3100 Software Development Kit CRITICAL 9.8
CVE-2021-22671

Multiple integer overflow issues exist while processing long domain names, which may allow an attacker to remotely execute code on the SimpleLink Wi-…

Fix: 4.10.03 / 4.40.00+
Fix from $2,300 2021-05-07
Cc3100 Software Development Kit HIGH 7.2
CVE-2021-22675

The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to rem…

Fix: 4.10.03 / 4.40.00+
Fix from $1,950 2021-05-07
Cc3100 Software Development Kit CRITICAL 9.8
CVE-2021-22679

The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the …

Fix: 4.10.03 / 4.40.00+
Fix from $2,300 2021-05-07
Apq8009w Firmware HIGH 7.8
CVE-2021-1895

Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voic…

Patch available
Fix from $1,950 2021-05-07
Apq8009 Firmware CRITICAL 9.8
CVE-2020-11279

Memory corruption while processing crafted SDES packets due to improper length check in sdes packets recieved in Snapdragon Auto, Snapdragon Compute,…

Mitigation only
Fix from $2,300 2021-05-07
Exim HIGH 7.8
CVE-2020-28009

Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow because get_stdinput allows unbounded reads that are accompanied by unbounded increas…

Fix: 4.94.2+
Fix from $1,950 2021-05-06
Exim CRITICAL 9.8
CVE-2020-28017EPSS 37%

Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: r…

Fix: 4.94.1+
Fix from $2,300 2021-05-06
Exim CRITICAL 9.8
CVE-2020-28020EPSS 8%

Exim 4 before 4.92 allows Integer Overflow to Buffer Overflow, in which an unauthenticated remote attacker can execute arbitrary code by leveraging t…

Fix: 4.92+
Fix from $2,300 2021-05-06
Redis HIGH 8.8
CVE-2021-29477

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Red…

Fix: 6.0.13 / 6.2.3+
Fix from $1,950 2021-05-04
Redis HIGH 8.8
CVE-2021-29478

Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Red…

Fix: 6.2.3+
Fix from $1,950 2021-05-04
Debian Linux CRITICAL 9.8
CVE-2021-31870

An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer…

Fix: 2.0.9+
Fix from $2,300 2021-04-30
Debian Linux HIGH 7.5
CVE-2021-31871

An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dereference on 64-bit systems.

Fix: 2.0.9+
Fix from $1,950 2021-04-30
Debian Linux CRITICAL 9.8
CVE-2021-31872

An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overf…

Fix: 2.0.9+
Fix from $2,300 2021-04-30
Debian Linux CRITICAL 9.8
CVE-2021-31873

An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer over…

Fix: 2.0.9+
Fix from $2,300 2021-04-30