Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Openvpn HIGH 7.8
CVE-2024-27459EPSS 8%

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary …

Fix: 2.5.10 / 2.6.10+
Fix from $1,950 2024-07-08
Ghostscript HIGH 8.8
CVE-2024-29506

Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.

Fix: 10.03.0+
Fix from $1,950 2024-07-03
Ghostscript HIGH 8.8
CVE-2024-29509

Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.

Fix: 10.03.0+
Fix from $1,950 2024-07-03
Rtsper HIGH 7.8
CVE-2022-25480

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUe…

Fix: 10.0.22000.21355 / 10.0.22000.31274+
Fix from $1,950 2024-07-02
Unclassified HIGH 7.8
CVE-2024-4467

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing blo…

Mitigation only
Fix from $1,950 2024-07-02
Windriver MEDIUM 5.5
CVE-2024-22103

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service …

Fix: 12.6.0+
Fix from $1,600 2024-07-02
Windriver MEDIUM 5.5
CVE-2024-22104

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service …

Fix: 12.5.1+
Fix from $1,600 2024-07-02
Windriver MEDIUM 5.5
CVE-2023-51778

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service …

Fix: 12.1.0+
Fix from $1,600 2024-07-02
Android HIGH 7.8
CVE-2024-20901

Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds m…

Mitigation only
Fix from $1,950 2024-07-02
Android HIGH 7.8
CVE-2024-20893

Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.

Mitigation only
Fix from $1,950 2024-07-02
Openharmony CRITICAL 9.8
CVE-2024-37077

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Fix: after 4.0
Fix from $2,300 2024-07-02
Openharmony CRITICAL 9.8
CVE-2024-37185

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Fix: after 4.0
Fix from $2,300 2024-07-02
Openharmony CRITICAL 9.8
CVE-2024-36243

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.

Fix: after 4.0
Fix from $2,300 2024-07-02
Openharmony CRITICAL 9.8
CVE-2024-36260

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Fix: after 4.0
Fix from $2,300 2024-07-02
9205 Lte Modem Firmware HIGH 7.8
CVE-2024-21469

Memory corruption when an invoke call and a TEE call are bound for the same trusted application.

No fix yet
Fix from $1,950 2024-07-01
Aqt1000 Firmware HIGH 7.8
CVE-2023-43554

Memory corruption while processing IOCTL handler in FastRPC.

No fix yet
Fix from $1,950 2024-07-01
Android MEDIUM 6.2
CVE-2024-39430

In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no addition…

Mitigation only
Fix from $1,600 2024-07-01
Android MEDIUM 6.2
CVE-2024-39429

In faceid servive, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no addition…

Mitigation only
Fix from $1,600 2024-07-01
Android MEDIUM 6.7
CVE-2024-20079

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with Syst…

Mitigation only
Fix from $1,600 2024-07-01
Yocto MEDIUM 6.7
CVE-2024-20081

In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with Syst…

Mitigation only
Fix from $1,600 2024-07-01
Unclassified HIGH 8.8
CVE-2024-39840

Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain Lua base …

Mitigation only
Fix from $1,950 2024-06-29
Unclassified MEDIUM 6.5
CVE-2024-38533

ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access due to the addresses used to…

Mitigation only
Fix from $1,600 2024-06-28
A301 Firmware CRITICAL 9.8
CVE-2024-6403

A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is the function formWifiBasicSet …

No fix yet
Fix from $2,300 2024-06-28
A301 Firmware CRITICAL 9.8
CVE-2024-6402

A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the function fromSetWirelessRepeat of t…

No fix yet
Fix from $2,300 2024-06-28
Data Domain Operating System HIGH 8.8
CVE-2024-29176

Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with …

Fix: 5.16.0.0 / 7.7.5.40+
Fix from $1,950 2024-06-26
Squid MEDIUM 6.3
CVE-2024-37894EPSS 6%

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid i…

Fix: 6.10+
Fix from $1,600 2024-06-25
Autocad HIGH 7.8
CVE-2024-37006

A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by writ…

Fix: 2022.1.5 / 2023.1.6+
Fix from $1,950 2024-06-25
Autocad HIGH 7.8
CVE-2024-36999

A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Write. A malicious actor can l…

Fix: 2022.1.5 / 2023.1.6+
Fix from $1,950 2024-06-25
Autocad HIGH 7.8
CVE-2024-37003

A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack…

Fix: 2022.1.5 / 2023.1.6+
Fix from $1,950 2024-06-25
Autocad HIGH 7.8
CVE-2024-23154

A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A maliciou…

Fix: 2022.1.5 / 2023.1.6+
Fix from $1,950 2024-06-25