Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Android HIGH 7.8
CVE-2023-20985

In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to …

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-20966

In inflate of inflate.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with…

Mitigation only
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-20931

In avdt_scb_hdl_write_req of avdt_scb_act.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalat…

Patch available
Fix from $1,950 2023-03-24
Android HIGH 7.8
CVE-2023-20936

In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o…

Patch available
Fix from $1,950 2023-03-24
Android CRITICAL 9.8
CVE-2023-20951

In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code e…

Patch available
Fix from $2,300 2023-03-24
Android MEDIUM 5.5
CVE-2023-20952

In A2DP_BuildCodecHeaderSbc of a2dp_sbc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local informati…

Patch available
Fix from $1,600 2023-03-24
Android CRITICAL 9.8
CVE-2023-20954

In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution …

Patch available
Fix from $2,300 2023-03-24
Upx HIGH 7.5
CVE-2021-43311

A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem …

Fix: 4.0.0+
Fix from $1,950 2023-03-24
Upx HIGH 7.5
CVE-2021-43312

A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in t…

Fix: 4.0.0+
Fix from $1,950 2023-03-24
Upx HIGH 7.5
CVE-2021-43313

A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in t…

Fix: 4.0.0+
Fix from $1,950 2023-03-24
Upx HIGH 7.5
CVE-2021-43314

A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem…

Fix: 4.0.0+
Fix from $1,950 2023-03-24
Upx HIGH 7.5
CVE-2021-43315

A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem…

Fix: 4.0.0+
Fix from $1,950 2023-03-24
Upx HIGH 7.5
CVE-2021-43316

A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le64().

Fix: 4.0.0+
Fix from $1,950 2023-03-24
Upx HIGH 7.5
CVE-2021-43317

A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem…

Fix: 4.0.0+
Fix from $1,950 2023-03-24
Android CRITICAL 9.8
CVE-2022-42498

In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no a…

Mitigation only
Fix from $2,300 2023-03-24
Android CRITICAL 9.8
CVE-2022-42499

In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code…

Mitigation only
Fix from $2,300 2023-03-24
Deno Runtime CRITICAL 9.8
CVE-2023-28445

Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are s…

Patch available
Fix from $2,300 2023-03-24
Flexipdf HIGH 7.8
CVE-2023-24295

A stack overfow in SoftMaker Software GmbH FlexiPDF v3.0.3.0 allows attackers to execute arbitrary code after opening a crafted PDF file.

No fix yet
Fix from $1,950 2023-03-23
Adaptive Security Appliance Software MEDIUM 5.9
CVE-2023-20081

A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Sof…

Mitigation only
Fix from $1,600 2023-03-23
D901 Firmware HIGH 7.5
CVE-2023-27077

Stack Overflow vulnerability found in 360 D901 allows a remote attacker to cause a Distributed Denial of Service (DDOS) via a crafted HTTP package.

No fix yet
Fix from $1,950 2023-03-23
Exynos Modem 5300 Firmware CRITICAL 9.8
CVE-2023-26496EPSS 23%

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5124. M…

Mitigation only
Fix from $2,300 2023-03-23
Swftools MEDIUM 5.5
CVE-2023-27249

swfdump v0.9.2 was discovered to contain a heap buffer overflow in the function swf_GetPlaceObject at swfobject.c.

No fix yet
Fix from $1,600 2023-03-23
Exynos Modem 5300 Firmware CRITICAL 9.8
CVE-2023-26498EPSS 23%

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos Auto T5126. Memor…

Mitigation only
Fix from $2,300 2023-03-23
Illustrator HIGH 7.8
CVE-2023-25860

Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary…

Fix: 27.3.1+
Fix from $1,950 2023-03-22
Illustrator HIGH 7.8
CVE-2023-25861

Illustrator version 26.5.2 (and earlier) and 27.2.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary…

Fix: 27.3.1+
Fix from $1,950 2023-03-22
Vox2mesh MEDIUM 5.5
CVE-2023-27754

vox2mesh 1.0 has stack-overflow in main.cpp, this is stack-overflow caused by incorrect use of memcpy() funciton. The flow allows an attacker to caus…

No fix yet
Fix from $1,600 2023-03-22
Exynos Modem 5300 Firmware CRITICAL 9.8
CVE-2023-26497EPSS 23%

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5125. M…

Mitigation only
Fix from $2,300 2023-03-21
Chrome CRITICAL 9.8
CVE-2023-1529

Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a…

Fix: 111.0.5563.110+
Fix from $2,300 2023-03-21
Linux Kernel HIGH 7.8
CVE-2022-48423

In the Linux kernel before 6.1.3, fs/ntfs3/record.c does not validate resident attribute names. An out-of-bounds write may occur.

Fix: 6.1.3+
Fix from $1,950 2023-03-19
W20e Firmware CRITICAL 9.8
CVE-2023-26805

Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify.

No fix yet
Fix from $2,300 2023-03-19