Vulnerability index

Browse CVEs

771 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Reachable AssertionCWE-617 × clear
Firefox HIGH 8.8
CVE-2020-15670

Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we pres…

Fix: 78.2 / 80.0+
Fix from $1,950 2020-10-01
Tensorflow MEDIUM 5.3
CVE-2020-15194

In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the sh…

Fix: 1.15.4 / 2.0.3+
Fix from $1,600 2020-09-25
Tensorflow MEDIUM 6.3
CVE-2020-15197

In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tenso…

Patch available
Fix from $1,600 2020-09-25
Debian Linux HIGH 7.5
CVE-2020-6097

An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequenc…

No fix yet
Fix from $1,950 2020-09-10
Apq8098 Firmware HIGH 7.5
CVE-2020-11135

u'Reachable assertion when wrong data size is returned by parser for ape clips' in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IO…

Mitigation only
Fix from $1,950 2020-09-09
Esp Idf MEDIUM 6.5
CVE-2020-13595

The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of complet…

Fix: after 4.2
Fix from $1,600 2020-08-31
Ubuntu Linux HIGH 7.5
CVE-2020-8620

In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can explo…

Fix: after 9.17.3
Fix from $1,950 2020-08-21
Ubuntu Linux HIGH 7.5
CVE-2020-8621

In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send …

Fix: 2.2.2-5027+
Fix from $1,950 2020-08-21
Fedora MEDIUM 6.5
CVE-2020-8622EPSS 6%

In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacke…

Fix: 2.2.2-5028+
Fix from $1,600 2020-08-21
Fedora HIGH 7.5
CVE-2020-8623EPSS 6%

In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attac…

Fix: 2.2.2-5027+
Fix from $1,950 2020-08-21
Firefox HIGH 8.8
CVE-2020-12417

Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially…

Fix: 68.10.0 / 78.0+
Fix from $1,950 2020-07-09
Enterprise Linux MEDIUM 5.0
CVE-2020-10761

An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-cli…

Fix: 5.0.1+
Fix from $1,600 2020-06-09
Ipq6018 Firmware HIGH 7.5
CVE-2020-3645

Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes in Snapdragon Compute, Snapd…

Mitigation only
Fix from $1,950 2020-06-02
Apq8009 Firmware CRITICAL 9.8
CVE-2020-3615

Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to improper en…

Patch available
Fix from $2,300 2020-06-02
Fusion MEDIUM 5.5
CVE-2020-3958

VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x be…

Fix: 11.5.2 / 15.5.2+
Fix from $1,600 2020-05-29
Jerryscript HIGH 7.5
CVE-2020-13649

parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_info_list…

Patch available
Fix from $1,950 2020-05-28
Jerryscript HIGH 7.5
CVE-2020-13622

JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintende…

Patch available
Fix from $1,950 2020-05-27
Debian Linux MEDIUM 5.9
CVE-2020-8617EPSS 93%

Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfu…

Fix: after 9.17.1
Fix from $1,600 2020-05-19
Apq8009 Firmware HIGH 7.5
CVE-2020-3651

Active command timeout since WM status change cmd is not removed from active queue if peer sends multiple deauth frames. in Snapdragon Auto, Snapdrag…

Patch available
Fix from $1,950 2020-04-16
Apq8096au Firmware HIGH 7.5
CVE-2019-14022

Error occurs While extracting the ipv6_header having an invalid length due to lack of length check in Snapdragon Auto, Snapdragon Compute, Snapdragon…

Mitigation only
Fix from $1,950 2020-04-16
Debian Linux HIGH 7.5
CVE-2020-11653

An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a …

Fix: 6.0.6 / 6.2.3+
Fix from $1,950 2020-04-08
Apq8017 Firmware HIGH 7.8
CVE-2019-14049

Stage-2 fault will occur while writing to an ION system allocation which has been assigned to non-HLOS memory which is non-standard in Snapdragon Aut…

Patch available
Fix from $1,950 2020-02-07
Lldpd HIGH 7.5
CVE-2015-8012

lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet.

Fix: 0.8.0+
Fix from $1,950 2020-01-28
Stb Truetype.h HIGH 8.8
CVE-2020-6617

stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.

Fix: after 1.22
Fix from $1,950 2020-01-08
Stb Truetype.h HIGH 8.8
CVE-2020-6619

stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.

Fix: after 1.22
Fix from $1,950 2020-01-08
Stb Truetype.h HIGH 8.8
CVE-2020-6623

stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.

Fix: after 1.22
Fix from $1,950 2020-01-08
Stb Image.h MEDIUM 6.5
CVE-2019-20056

stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.

No fix yet
Fix from $1,600 2019-12-29
Debian Linux HIGH 7.5
CVE-2011-3596EPSS 11%

Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.

Fix: 1.0.4.1+
Fix from $1,950 2019-11-26
Debian Linux MEDIUM 6.5
CVE-2012-5521

quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal

Mitigation only
Fix from $1,600 2019-11-25
Acrn HIGH 7.5
CVE-2019-18844

The Device Model in ACRN before 2019w25.5-140000p relies on assert calls in devicemodel/hw/pci/core.c and devicemodel/include/pci_core.h (instead of …

Fix: 2019w25.5-140000p+
Fix from $1,950 2019-11-13