Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Android MEDIUM 6.7
CVE-2021-0407

In clk driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System…

Mitigation only
Fix from $1,600 2021-08-18
Android MEDIUM 6.7
CVE-2021-0626

In ged, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…

Mitigation only
Fix from $1,600 2021-08-18
Android MEDIUM 6.7
CVE-2021-0628

In OMA DRM, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with System exec…

Mitigation only
Fix from $1,600 2021-08-18
Xmill CRITICAL 9.8
CVE-2021-21825

A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.…

No fix yet
Fix from $2,300 2021-08-18
Bento4 HIGH 7.5
CVE-2020-23332

A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByteStream.cpp of Bento4 version…

No fix yet
Fix from $1,950 2021-08-17
Bento4 HIGH 7.5
CVE-2020-23333

A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 version 06c39d9. This can lead …

Fix: 1.6.0-635+
Fix from $1,950 2021-08-17
Bento4 HIGH 7.5
CVE-2020-23334

A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c39d9 can lead to a segmentatio…

Fix: 1.6.0-635+
Fix from $1,950 2021-08-17
Firefox HIGH 8.8
CVE-2021-29988

Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentiall…

Fix: 78.13.0 / 91.0+
Fix from $1,950 2021-08-17
Firefox HIGH 8.8
CVE-2021-29989

Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corruption a…

Fix: 78.13.0 / 91.0+
Fix from $1,950 2021-08-17
Firefox HIGH 8.8
CVE-2021-29990

Mozilla developers and community members reported memory safety bugs present in Firefox 90. Some of these bugs showed evidence of memory corruption a…

Fix: 91.0+
Fix from $1,950 2021-08-17
Xmill CRITICAL 9.8
CVE-2021-21810

A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead…

No fix yet
Fix from $2,300 2021-08-17
Firefox HIGH 8.8
CVE-2021-29984

Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This…

Fix: 78.13.0 / 91.0+
Fix from $1,950 2021-08-17
Android HIGH 7.8
CVE-2021-0646

In sqlite3_str_vappendf of sqlite3.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation o…

Mitigation only
Fix from $1,950 2021-08-17
Android HIGH 7.8
CVE-2021-0519

In BITSTREAM_FLUSH of ih264e_bitstream.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local information…

Patch available
Fix from $1,950 2021-08-17
Android HIGH 7.8
CVE-2021-0573

In asf extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no add…

Mitigation only
Fix from $1,950 2021-08-17
Android HIGH 7.8
CVE-2021-0574

In asf extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no add…

Mitigation only
Fix from $1,950 2021-08-17
Android HIGH 7.8
CVE-2021-0576

In flv extractor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no add…

Mitigation only
Fix from $1,950 2021-08-17
Android HIGH 7.8
CVE-2021-0640

In noteAtomLogged of StatsdStats.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p…

Mitigation only
Fix from $1,950 2021-08-17
Rtl819x Jungle Software Development Kit HIGH 7.5
CVE-2021-35392EPSS 83%

Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usu…

Fix: after 3.4.14b
Fix from $1,950 2021-08-16
Rtl819x Jungle Software Development Kit CRITICAL 9.8
CVE-2021-35393EPSS 70%

Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usu…

Fix: after 3.4.14b
Fix from $2,300 2021-08-16
Xmill HIGH 7.8
CVE-2021-21812

A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’ Xmill 0.7. Within the functi…

No fix yet
Fix from $1,950 2021-08-13
Xmill HIGH 7.8
CVE-2021-21813

Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the command line. filepattern is passed…

No fix yet
Fix from $1,950 2021-08-13
Xmill HIGH 7.8
CVE-2021-21815

A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs' Xmill 0.7. Within the functi…

No fix yet
Fix from $1,950 2021-08-13
Bento4 MEDIUM 6.5
CVE-2020-21066

An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a denial of …

No fix yet
Fix from $1,600 2021-08-13
Xmill CRITICAL 9.8
CVE-2021-21829

A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs’ Xmill …

No fix yet
Fix from $2,300 2021-08-13
Xmill CRITICAL 9.8
CVE-2021-21830

A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7. A specially crafted…

No fix yet
Fix from $2,300 2021-08-13
Polipo HIGH 7.5
CVE-2021-38614

Polipo through 1.1.1, when NDEBUG is used, allows a heap-based buffer overflow during parsing of a Range header. NOTE: This vulnerability only affect…

Fix: after 1.1.1
Fix from $1,950 2021-08-12
Tensorflow HIGH 7.8
CVE-2021-37650

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.ExperimentalDatasetToT…

Fix: 2.3.4 / 2.4.3+
Fix from $1,950 2021-08-12
Tensorflow HIGH 7.8
CVE-2021-37651

TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.raw_ops.FractionalAvgPoolGrad`…

Fix: 2.3.4 / 2.4.3+
Fix from $1,950 2021-08-12
Windows 10 MEDIUM 6.8
CVE-2021-34480EPSS 40%

Scripting Engine Memory Corruption Vulnerability

Patch available
Fix from $1,600 2021-08-12