Vulnerability index

Browse CVEs

3,271 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Fedora MEDIUM 5.5
CVE-2020-13999

ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF …

Fix: after 1.0.12
Fix from $1,600 2020-06-15
Android HIGH 7.8
CVE-2020-0216

In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local esca…

Patch available
Fix from $1,950 2020-06-11
Android HIGH 8.8
CVE-2020-0194

In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to r…

Patch available
Fix from $1,950 2020-06-11
Ubuntu Linux HIGH 7.5
CVE-2020-0198

In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of servic…

Fix: 0.6.22_p20201105+
Fix from $1,950 2020-06-11
Fedora HIGH 7.5
CVE-2020-0181

In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial o…

Fix: 0.6.22_p20201105+
Fix from $1,950 2020-06-11
Android MEDIUM 5.5
CVE-2020-0167

In load of ResourceTypes.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with…

Patch available
Fix from $1,600 2020-06-11
Android HIGH 7.5
CVE-2020-0128

In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to remote information disclosur…

Patch available
Fix from $1,950 2020-06-11
Android HIGH 7.8
CVE-2020-0136

In multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privi…

Patch available
Fix from $1,950 2020-06-11
Android CRITICAL 9.8
CVE-2020-0117

In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the bluet…

Patch available
Fix from $2,300 2020-06-10
Windows 10 HIGH 8.8
CVE-2020-1281EPSS 14%

A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution…

Patch available
Fix from $1,950 2020-06-09
Ipados HIGH 7.8
CVE-2020-9852

An integer overflow was addressed through improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13…

Fix: 6.2.5 / 10.15.5+
Fix from $1,950 2020-06-09
Mac Os X HIGH 7.8
CVE-2020-9841

An integer overflow was addressed through improved input validation. This issue is fixed in macOS Catalina 10.15.5. An application may be able to exe…

Fix: 10.15.5+
Fix from $1,950 2020-06-09
Linux Kernel HIGH 7.8
CVE-2020-13974

An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times i…

Fix: 4.4.227 / 4.9.227+
Fix from $1,950 2020-06-09
Zephyr HIGH 7.5
CVE-2020-10063

A remote adversary with the ability to send arbitrary CoAP packets to be parsed by Zephyr is able to cause a denial of service. This issue affects: z…

Fix: after 2.2.0
Fix from $1,950 2020-06-05
Zephyr CRITICAL 9.8
CVE-2020-10070

In the Zephyr Project MQTT code, improper bounds checking can result in memory corruption and possibly remote code execution. NCC-ZEP-031 This issue …

Fix: after 2.2.0
Fix from $2,300 2020-06-05
Perl HIGH 8.2
CVE-2020-10543EPSS 11%

Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.

Fix: 5.30.3+
Fix from $1,950 2020-06-05
Perl HIGH 8.6
CVE-2020-10878

Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could l…

Fix: 5.30.3+
Fix from $1,950 2020-06-05
Elliptic HIGH 7.7
CVE-2020-13822

The Elliptic package 6.5.2 for Node.js allows ECDSA signature malleability via variations in encoding, leading '\0' bytes, or integer overflows. This…

No fix yet
Fix from $1,950 2020-06-04
Apq8009 Firmware CRITICAL 9.8
CVE-2020-3641

Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdragon Auto, Snapdragon Compute,…

Mitigation only
Fix from $2,300 2020-06-02
Kamorta Firmware HIGH 7.8
CVE-2019-14066

Integer overflow in calculating estimated output buffer size when getting a list of installed Feature IDs, Serial Numbers or checking Feature ID stat…

Mitigation only
Fix from $1,950 2020-06-02
Upx MEDIUM 5.5
CVE-2019-20805

p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment.

Fix: 3.96+
Fix from $1,600 2020-06-01
Debian Linux MEDIUM 5.4
CVE-2020-11038

In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instru…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 6.8
CVE-2020-11039

In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and writte…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
SQLite MEDIUM 5.5
CVE-2020-13434

SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

Fix: 11.4+
Fix from $1,600 2020-05-24
PHP MEDIUM 5.3
CVE-2019-11048EPSS 6%

In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supplying overly long filenames or …

Fix: 7.2.31 / 7.3.18+
Fix from $1,600 2020-05-20
Ubuntu Linux MEDIUM 6.7
CVE-2020-10722

A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a sm…

Fix: after 18.05
Fix from $1,600 2020-05-19
Ubuntu Linux MEDIUM 6.7
CVE-2020-10723

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under c…

Fix: after 17.05
Fix from $1,600 2020-05-19
Nitro Pro HIGH 7.8
CVE-2020-6092EPSS 42%

An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger a…

No fix yet
Fix from $1,950 2020-05-18
Securecrt CRITICAL 9.8
CVE-2020-12651EPSS 7%

SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow because a banner can trigger a…

Fix: 2.4 / 8.7.2+
Fix from $2,300 2020-05-15
Ubuntu Linux MEDIUM 6.6
CVE-2020-11521

libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write.

Fix: 2.0.0+
Fix from $1,600 2020-05-15