Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
R 30ia Firmware HIGH 7.4
CVE-2021-32998

The FANUC R-30iA and R-30iB series controllers are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary co…

Mitigation only
Fix from $1,950 2022-01-10
Sonicos HIGH 8.8
CVE-2021-20046

A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (D…

Fix: after 7.0.1-5023-1349
Fix from $1,950 2022-01-10
Sonicos HIGH 8.8
CVE-2021-20048

A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) a…

Fix: after 7.0.1-5023-1349
Fix from $1,950 2022-01-10
Debian Linux MEDIUM 5.9
CVE-2022-22707EPSS 9%

In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes repr…

Fix: after 1.4.63
Fix from $1,600 2022-01-06
Insydeh2o HIGH 8.2
CVE-2021-45971

An issue was discovered in SdHostDriver in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.…

Fix: 5.16.25 / 5.26.25+
Fix from $1,950 2022-01-06
Insydeh2o HIGH 8.2
CVE-2021-45969

An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43…

Fix: 5.16.25 / 5.26.25+
Fix from $1,950 2022-01-05
Insydeh2o HIGH 8.2
CVE-2021-45970

An issue was discovered in IdeBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.…

Fix: 5.16.25 / 5.26.25+
Fix from $1,950 2022-01-05
Hdf5 MEDIUM 5.5
CVE-2021-45833

A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in /hdf5/src/H5Dchunk.c, which …

No fix yet
Fix from $1,600 2022-01-05
Hdf5 MEDIUM 5.5
CVE-2021-45830

A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Servi…

No fix yet
Fix from $1,600 2022-01-05
Cloud Foundation HIGH 7.8
CVE-2021-22045

VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contai…

Fix: 12.2.0 / 16.2.0+
Fix from $1,950 2022-01-04
Whatsapp CRITICAL 9.8
CVE-2021-24042

The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, W…

Fix: 2.21.23 / 2.21.230+
Fix from $2,300 2022-01-04
Android MEDIUM 6.7
CVE-2022-20014

In vow driver, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System e…

Mitigation only
Fix from $1,600 2022-01-04
Harmonyos CRITICAL 9.8
CVE-2021-39990

The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may affect user experience.

Fix: 2.0+
Fix from $2,300 2022-01-03
Csr8510 A10 Firmware MEDIUM 6.5
CVE-2021-35093

Possible memory corruption in BT controller when it receives an oversized LMP packet over 2-DH1 link and leads to denial of service in BlueCore

Mitigation only
Fix from $1,600 2022-01-03
Fedora MEDIUM 5.5
CVE-2021-45942

OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider…

Fix: 3.1.4+
Fix from $1,600 2022-01-01
Debian Linux MEDIUM 5.5
CVE-2021-45943

GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and …

Fix: after 3.4.0
Fix from $1,600 2022-01-01
Mdbtools HIGH 7.8
CVE-2021-45926

MDB Tools (aka mdbtools) 0.9.2 has a stack-based buffer overflow (at 0x7ffd0c689be0) in mdb_numeric_to_string (called from mdb_xfer_bound_data and _m…

Patch available
Fix from $1,950 2022-01-01
Mdbtools HIGH 7.8
CVE-2021-45927

MDB Tools (aka mdbtools) 0.9.2 has a stack-based buffer overflow (at 0x7ffd6e029ee0) in mdb_numeric_to_string (called from mdb_xfer_bound_data and _m…

Patch available
Fix from $1,950 2022-01-01
Libjxl MEDIUM 5.5
CVE-2021-45928

libjxl b02d6b9, as used in libvips 8.11 through 8.11.2 and other products, has an out-of-bounds write in jxl::ModularFrameDecoder::DecodeGroup (calle…

Fix: 0.6.1+
Fix from $1,600 2022-01-01
Fedora MEDIUM 5.5
CVE-2021-45930

Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend…

Fix: after 6.2.1
Fix from $1,600 2022-01-01
Fedora MEDIUM 6.5
CVE-2021-45931

HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45932

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (4 bytes) in MqttDecode_Publish (called from MqttClient_DecodePacket and MqttClient_HandlePacke…

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45933

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (8 bytes) in MqttDecode_Publish (called from MqttClient_DecodePacket and MqttClient_HandlePacke…

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45934

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_HandlePacket and MqttClient_WaitType).

Patch available
Fix from $1,600 2022-01-01
Grok MEDIUM 5.5
CVE-2021-45935

Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T…

No fix yet
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45936

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttDecode_Disconnect (called from MqttClient_DecodePacket and MqttClient_WaitType).

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45937

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and MqttClient_Connect).

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45938

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and MqttClient_Unsubscribe).

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45939

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and MqttClient_Subscribe).

Patch available
Fix from $1,600 2022-01-01
Libbpf MEDIUM 6.5
CVE-2021-45940

libbpf 0.6.0 and 0.6.1 has a heap-based buffer overflow (4 bytes) in __bpf_object__open (called from bpf_object__open_mem and bpf-object-fuzzer.c).

No fix yet
Fix from $1,600 2022-01-01