Vulnerability index

Browse CVEs

3,271 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Apq8009 Firmware HIGH 7.8
CVE-2019-10615

u'Possibility of integer overflow in keymaster 4 while allocating memory due to multiplication of large numcerts value and size of keymaster bob whic…

Mitigation only
Fix from $1,950 2020-09-08
Apq8009 Firmware HIGH 7.8
CVE-2019-13994

u'Lack of check that the current received data fragment size of a particular packet that are read from shared memory are less than the actual packet …

Mitigation only
Fix from $1,950 2020-09-08
Apq8009 Firmware HIGH 7.8
CVE-2019-13995

u'Lack of integer overflow check for addition of fragment size and remaining size that are read from shared memory can lead to memory corruption and …

Mitigation only
Fix from $1,950 2020-09-08
Apq8009 Firmware HIGH 7.8
CVE-2019-13998

u'Lack of check that the TX FIFO write and read indices that are read from shared RAM are less than the FIFO size results into memory corruption and …

Mitigation only
Fix from $1,950 2020-09-08
Apq8009 Firmware HIGH 7.8
CVE-2019-13999

u'Lack of check for integer overflow for round up and addition operations result into memory corruption and potential information leakage' in Snapdra…

Mitigation only
Fix from $1,950 2020-09-08
Kamorta Firmware HIGH 7.8
CVE-2019-14056

u'Possible integer overflow in API due to lack of check on large oid range count in cert extension field' in Snapdragon Auto, Snapdragon Compute, Sna…

Mitigation only
Fix from $1,950 2020-09-08
Apq8009 Firmware HIGH 7.8
CVE-2019-14074

u'Heap overflow in diag command handler due to lack of check of packet length received from user' in Snapdragon Auto, Snapdragon Compute, Snapdragon …

Mitigation only
Fix from $1,950 2020-09-08
Parallels Desktop HIGH 8.8
CVE-2020-17396

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain…

Fix: 16.0.0+
Fix from $1,950 2020-08-25
P30 Pro Firmware MEDIUM 5.5
CVE-2020-9095

HUAWEI P30 Pro smartphone with Versions earlier than 10.1.0.160(C00E160R2P8) has an integer overflow vulnerability. Some functions are lack of verifi…

Fix: 10.1.0.160+
Fix from $1,600 2020-08-21
Avian HIGH 7.8
CVE-2020-17360

An issue was discovered in ReadyTalk Avian 1.2.0. The vm::arrayCopy method defined in classpath-common.h contains multiple boundary checks that are p…

Mitigation only
Fix from $1,950 2020-08-12
Horndis MEDIUM 5.9
CVE-2020-15137

All versions of HoRNDIS are affected by an integer overflow in the RNDIS packet parsing routines. A malicious USB device can trigger disclosure of un…

Mitigation only
Fix from $1,600 2020-08-12
Android HIGH 8.8
CVE-2020-0240

In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution wi…

Mitigation only
Fix from $1,950 2020-08-11
Fedora MEDIUM 6.7
CVE-2020-14344

An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. A…

Fix: 1.6.10+
Fix from $1,600 2020-08-05
Enterprise Linux MEDIUM 6.0
CVE-2020-14310

There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in byt…

Fix: 2.06+
Fix from $1,600 2020-07-31
Enterprise Linux MEDIUM 6.0
CVE-2020-14311

There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode siz…

Fix: 2.06+
Fix from $1,600 2020-07-31
Grub2 MEDIUM 6.7
CVE-2020-14309

There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 byte…

Fix: 2.06+
Fix from $1,600 2020-07-30
Grub2 MEDIUM 6.4
CVE-2020-14308

In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads …

Fix: 2.06+
Fix from $1,600 2020-07-29
Manageengine Desktop Central CRITICAL 9.8
CVE-2020-15588EPSS 13%

An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer over…

Fix: 10.0.561+
Fix from $2,300 2020-07-29
Enterprise Linux Atomic Host MEDIUM 6.4
CVE-2020-15707

Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red…

Fix: after 2.04
Fix from $1,600 2020-07-29
R6700 Firmware HIGH 8.8
CVE-2020-10929

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. …

Mitigation only
Fix from $1,950 2020-07-28
Chrome HIGH 8.8
CVE-2020-6523

Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 84.0.4147.89+
Fix from $1,950 2020-07-22
Firefox HIGH 8.8
CVE-2018-12371

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This resul…

Fix: 60.0 / 60.1.0+
Fix from $1,950 2020-07-09
Node.bcrypt.js HIGH 7.5
CVE-2020-7689

Data is truncated wrong when its length is greater than 255 bytes.

Fix: 5.0.0+
Fix from $1,950 2020-07-01
Fedora MEDIUM 6.5
CVE-2020-4030

In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. T…

Fix: 2.1.2+
Fix from $1,600 2020-06-22
Apq8009 Firmware HIGH 7.8
CVE-2019-14094

Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet in Snapdragon Auto, Snapdrago…

Mitigation only
Fix from $1,950 2020-06-22
Mbed Coap HIGH 7.5
CVE-2020-12887

Memory leaks were discovered in the CoAP library in Arm Mbed OS 5.15.3 when using the Arm mbed-coap library 5.1.5. The CoAP parser is responsible for…

Patch available
Fix from $1,950 2020-06-18
Debian Linux MEDIUM 6.5
CVE-2020-14401

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.

Fix: 0.9.13 / 3.2.1.0+
Fix from $1,600 2020-06-17
Tcp\/ip HIGH 7.3
CVE-2020-11904

The Treck TCP/IP stack before 6.0.1.66 has an Integer Overflow during Memory Allocation that causes an Out-of-Bounds Write.

Fix: 6.0.1.66+
Fix from $1,950 2020-06-17
Redis HIGH 7.7
CVE-2020-14147

An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code i…

Fix: 5.0.9 / 6.0.3+
Fix from $1,950 2020-06-15
GitLab MEDIUM 5.3
CVE-2020-14155

libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.

Fix: 8.44 / 11.0.1+
Fix from $1,600 2020-06-15