Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Libbpf MEDIUM 6.5
CVE-2021-45941

libbpf 0.6.0 and 0.6.1 has a heap-based buffer overflow (8 bytes) in __bpf_object__open (called from bpf_object__open_mem and bpf-object-fuzzer.c).

No fix yet
Fix from $1,600 2022-01-01
Wasm3 MEDIUM 5.5
CVE-2021-45929

Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from CompileElseBlock and Compile_If).

No fix yet
Fix from $1,600 2022-01-01
Wasm3 MEDIUM 5.5
CVE-2021-45946

Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from Compile_LoopOrBlock and CompileBlockStatements).

No fix yet
Fix from $1,600 2022-01-01
Wasm3 MEDIUM 5.5
CVE-2021-45947

Wasm3 0.5.0 has an out-of-bounds write in Runtime_Release (called from EvaluateExpression and InitDataSegments).

No fix yet
Fix from $1,600 2022-01-01
Assimp MEDIUM 5.5
CVE-2021-45948

Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d_load and Assimp::M3DWrapper:…

No fix yet
Fix from $1,600 2022-01-01
Debian Linux MEDIUM 5.5
CVE-2021-45949

Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).

Fix: after 9.54.0
Fix from $1,600 2022-01-01
Libredwg MEDIUM 6.5
CVE-2021-45950

LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object).

Fix: after 0.12.4.4367
Fix from $1,600 2022-01-01
Dnsmasq CRITICAL 9.8
CVE-2021-45951

Dnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckForBogusWildcard). NOTE: the ve…

No fix yet
Fix from $2,300 2022-01-01
Dnsmasq CRITICAL 9.8
CVE-2021-45952

Dnsmasq 2.86 has a heap-based buffer overflow in dhcp_reply (called from dhcp_packet and FuzzDhcp). NOTE: the vendor's position is that CVE-2021-4595…

No fix yet
Fix from $2,300 2022-01-01
Dnsmasq CRITICAL 9.8
CVE-2021-45953

Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from hash_questions and fuzz_util.c). NOTE: the vendor's position is that CVE-2…

No fix yet
Fix from $2,300 2022-01-01
Dnsmasq CRITICAL 9.8
CVE-2021-45954

Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from answer_auth and FuzzAuth). NOTE: the vendor's position is that CVE-2021-45…

No fix yet
Fix from $2,300 2022-01-01
Dnsmasq CRITICAL 9.8
CVE-2021-45955

Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper boun…

No fix yet
Fix from $2,300 2022-01-01
Dnsmasq CRITICAL 9.8
CVE-2021-45956

Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply). NOTE: the vendor's position is that CVE-2021-4595…

No fix yet
Fix from $2,300 2022-01-01
Dnsmasq CRITICAL 9.8
CVE-2021-45957

Dnsmasq 2.86 has a heap-based buffer overflow in answer_request (called from FuzzAnswerTheRequest and fuzz_rfc1035.c). NOTE: the vendor's position is…

No fix yet
Fix from $2,300 2022-01-01
Ultrajson MEDIUM 5.5
CVE-2021-45958

UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for exa…

Fix: 5.2.0+
Fix from $1,600 2022-01-01
Winproladder HIGH 7.8
CVE-2021-43554

FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to an out-of-bounds write while processing project files, which may allow an attacker…

Fix: after 3.30_24518
Fix from $1,950 2021-12-28
Winproladder HIGH 7.8
CVE-2021-43556

FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing project files, which may allow an a…

Fix: after 3.30_24518
Fix from $1,950 2021-12-28
Gif2apng HIGH 7.8
CVE-2021-45907

An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a for loop. An attacker has little influence over the data …

No fix yet
Fix from $1,950 2021-12-28
Gif2apng HIGH 7.8
CVE-2021-45908

An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a while loop. An attacker has little influence over the dat…

No fix yet
Fix from $1,950 2021-12-28
Debian Linux HIGH 7.8
CVE-2021-45909

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to writ…

No fix yet
Fix from $1,950 2021-12-28
Debian Linux HIGH 7.8
CVE-2021-45910

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside …

No fix yet
Fix from $1,950 2021-12-28
Debian Linux HIGH 7.8
CVE-2021-45911

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attacker to write 2 bytes outside t…

No fix yet
Fix from $1,950 2021-12-28
Metrics Util HIGH 8.1
CVE-2021-45704

An issue was discovered in the metrics-util crate before 0.7.0 for Rust. There is a data race and memory corruption because AtomicBucket<T> unconditi…

Fix: 0.7.0+
Fix from $1,950 2021-12-27
Nix CRITICAL 9.8
CVE-2021-45707

An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x before 0.21.2, and 0.22.x before 0.22.2 for Rust. unistd::getgrouplis…

Fix: 0.20.2 / 0.21.2+
Fix from $2,300 2021-12-27
Actix Web CRITICAL 9.8
CVE-2018-25025

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly extend the lifetime of a string, leading to memory corruption.

Fix: 0.7.15+
Fix from $2,300 2021-12-27
Actix Web CRITICAL 9.8
CVE-2018-25026

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can add the Send marker trait to an object that cannot be sent between thre…

Fix: 0.7.15+
Fix from $2,300 2021-12-27
Vec Const HIGH 7.5
CVE-2021-45680

An issue was discovered in the vec-const crate before 2.0.0 for Rust. It tries to construct a Vec from a pointer to a const slice, leading to memory …

Fix: 2.0.0+
Fix from $1,950 2021-12-27
Derive Com Impl HIGH 7.5
CVE-2021-45681

An issue was discovered in the derive-com-impl crate before 0.1.2 for Rust. An invalid reference (and memory corruption) can occur because AddRef mig…

Fix: 0.1.2+
Fix from $1,950 2021-12-27
Actix Web CRITICAL 9.8
CVE-2018-25024

An issue was discovered in the actix-web crate before 0.7.15 for Rust. It can unsoundly coerce an immutable reference into a mutable reference, leadi…

Fix: 0.7.15+
Fix from $2,300 2021-12-27
D7000 Firmware HIGH 8.8
CVE-2021-45636

NETGEAR D7000 devices before 1.0.1.82 are affected by a stack-based buffer overflow by an unauthenticated attacker.

Fix: 1.0.1.82+
Fix from $1,950 2021-12-26