Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Gpu Display Driver HIGH 7.8
CVE-2022-31610

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabilities ca…

Fix: 11.8 / 13.3+
Fix from $1,950 2022-11-19
Gpu Display Driver HIGH 7.8
CVE-2022-31606

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a failure to …

Fix: 11.8 / 13.3+
Fix from $1,950 2022-11-19
Tensorflow CRITICAL 9.8
CVE-2022-41900

TensorFlow is an open source platform for machine learning. The security vulnerability results in FractionalMax(AVG)Pool with illegal pooling_ratio. …

Fix: 2.8.4 / 2.9.3+
Fix from $2,300 2022-11-18
Gecko Software Development Kit MEDIUM 6.5
CVE-2022-24939

 A malformed packet containing an invalid destination address, causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to …

Mitigation only
Fix from $1,600 2022-11-18
Lief MEDIUM 6.5
CVE-2022-43171

A heap buffer overflow in the LIEF::MachO::BinaryParser::parse_dyldinfo_generic_bind function of LIEF v0.12.1 allows attackers to cause a Denial of S…

Patch available
Fix from $1,600 2022-11-17
Android MEDIUM 6.7
CVE-2022-20460

In (TBD) mprot_unmap? of (TBD), there is a possible way to corrupt the memory mapping due to improper input validation. This could lead to local esca…

Mitigation only
Fix from $1,600 2022-11-17
Android MEDIUM 6.7
CVE-2022-20428

In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with Syste…

No fix yet
Fix from $1,600 2022-11-17
Android MEDIUM 6.7
CVE-2022-20427

In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local escalation of privilege with …

Mitigation only
Fix from $1,600 2022-11-17
Kernel HIGH 8.2
CVE-2022-29276

SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corrupti…

Fix: 5.0.05.09.18 / 5.1.05.17.18+
Fix from $1,950 2022-11-15
Genoa Firmware HIGH 8.8
CVE-2022-29277

Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver,…

Fix: 05.36.10.0017 / 05.36.26.0016+
Fix from $1,950 2022-11-15
Micrium Uc Http CRITICAL 9.8
CVE-2022-24942

Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.

No fix yet
Fix from $2,300 2022-11-15
Kernel HIGH 8.2
CVE-2022-30771

Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm could lead…

Fix: 5.1.05.17.25 / 5.2.05.27.25+
Fix from $1,950 2022-11-15
Kernel HIGH 8.2
CVE-2022-30772

Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of the PnpSm…

Fix: 5.0.05.09.41 / 5.1.05.17.43+
Fix from $1,950 2022-11-15
Secure Firewall Threat Defense HIGH 7.5
CVE-2022-20946

A vulnerability in the generic routing encapsulation (GRE) tunnel decapsulation feature of Cisco Firepower Threat Defense (FTD) Software could allow …

Fix: after 7.0.3
Fix from $1,950 2022-11-15
Xpdf MEDIUM 5.5
CVE-2022-43071

A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted…

No fix yet
Fix from $1,600 2022-11-15
Aqt1000 Firmware CRITICAL 9.8
CVE-2022-33234

Memory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, S…

Mitigation only
Fix from $2,300 2022-11-15
W15e Firmware CRITICAL 9.8
CVE-2022-42058

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability…

No fix yet
Fix from $2,300 2022-11-15
W15e Firmware HIGH 7.5
CVE-2022-42060

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setWanPpoe function. This vulnerability allows …

No fix yet
Fix from $1,950 2022-11-15
Tasmota CRITICAL 9.8
CVE-2022-43294

Tasmota before commit 066878da4d4762a9b6cb169fdf353e804d735cfd was discovered to contain a stack overflow via the ClientPortPtr parameter at lib/libe…

Fix: 12.2.0+
Fix from $2,300 2022-11-14
Kernel MEDIUM 6.4
CVE-2022-32266

DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI handler and …

Fix: 5.3.05.36.23 / 5.4.05.44.23+
Fix from $1,600 2022-11-14
Xpdf MEDIUM 5.5
CVE-2022-43295

XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.

Mitigation only
Fix from $1,600 2022-11-14
Emberznet HIGH 7.5
CVE-2022-24938

A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.

Mitigation only
Fix from $1,950 2022-11-14
Htmldoc MEDIUM 5.5
CVE-2022-0137

A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries.

Fix: 1.9.15+
Fix from $1,600 2022-11-14
Software For Open Networking In The Cloud HIGH 7.5
CVE-2022-0324

There is a vulnerability in DHCPv6 packet parsing code that could be explored by remote attacker to craft a packet that could cause buffer overflow i…

Mitigation only
Fix from $1,950 2022-11-14
Bento4 HIGH 8.8
CVE-2022-3974

A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4_StdcFileByteStream::ReadPart…

No fix yet
Fix from $1,950 2022-11-13
Debian Linux HIGH 7.8
CVE-2022-45188

Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root…

Fix: after 3.1.13
Fix from $1,950 2022-11-12
Wi Fi 6e Ax411 Firmware MEDIUM 6.5
CVE-2022-28667

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi software before version 22.140 may allow an unauthenticated user to potentially enable den…

Fix: 22.140+
Fix from $1,600 2022-11-11
Xmm 7560 Firmware CRITICAL 9.6
CVE-2022-26513

Out-of-bounds write in some Intel(R) XMM(TM) 7560 Modem software before version M2_7560_R_01.2146.00 may allow an unauthenticated user to potentially…

Mitigation only
Fix from $2,300 2022-11-11
Fedora MEDIUM 6.5
CVE-2022-41854

Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied i…

Fix: 1.32+
Fix from $1,600 2022-11-11
Contiki Ng MEDIUM 5.4
CVE-2022-41873

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. Versions prior to 4.9 are vulnerable to an Out-of-boun…

Fix: 4.9+
Fix from $1,600 2022-11-11