Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Enterprise Linux CRITICAL 9.8
CVE-2021-20314

Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code executio…

Fix: 1.2.11+
Fix from $2,300 2021-08-12
Fabric Operating System HIGH 7.8
CVE-2021-27790

The command ipfilter in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses unsafe string function to proc…

Fix: 7.4.2h / 8.2.0_cbn4+
Fix from $1,950 2021-08-12
Wasm3 HIGH 7.5
CVE-2021-38592

Wasm3 0.5.0 has a heap-based buffer overflow in op_Const64 (called from EvaluateExpression and m3_LoadModule).

Mitigation only
Fix from $1,950 2021-08-12
Fedora HIGH 7.5
CVE-2021-38593

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaint…

Fix: 5.15.6+
Fix from $1,950 2021-08-12
Foxit Reader CRITICAL 9.8
CVE-2021-38568

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different …

Fix: 10.1.4+
Fix from $2,300 2021-08-11
Jetson Linux HIGH 7.8
CVE-2021-1106

NVIDIA Linux kernel distributions contain a vulnerability in nvmap, where writes may be allowed to read-only buffers, which may result in escalation …

Fix: 9.0 / 32.6.1+
Fix from $1,950 2021-08-11
Foxit Reader CRITICAL 9.8
CVE-2021-33793

Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office doc…

Fix: 10.1.4+
Fix from $2,300 2021-08-11
Fvdesigner HIGH 7.8
CVE-2021-32939

FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker t…

Fix: after 1.5.88
Fix from $1,950 2021-08-11
Fvdesigner HIGH 7.8
CVE-2021-32947

FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitra…

Fix: after 1.5.88
Fix from $1,950 2021-08-11
D3600 Firmware HIGH 7.2
CVE-2021-38525

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.…

Fix: 1.0.0.76 / 1.0.1.18+
Fix from $1,950 2021-08-11
R6400 Firmware HIGH 7.2
CVE-2021-38523

NETGEAR R6400 devices before 1.0.1.70 are affected by a stack-based buffer overflow by an authenticated user.

Fix: 1.0.1.70+
Fix from $1,950 2021-08-11
R6400 Firmware HIGH 7.2
CVE-2021-38522

NETGEAR R6400 devices before 1.0.1.52 are affected by a stack-based buffer overflow by an authenticated user.

Fix: 1.0.1.52+
Fix from $1,950 2021-08-11
R6400 Firmware HIGH 7.2
CVE-2021-38517

Certain NETGEAR devices are affected by out-of-bounds reads and writes. This affects R6400 before 1.0.1.70, RAX75 before 1.0.4.120, RAX80 before 1.0.…

Fix: 1.0.1.70 / 1.0.3.50+
Fix from $1,950 2021-08-11
Debian Linux MEDIUM 5.5
CVE-2020-21675

A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via conv…

Patch available
Fix from $1,600 2021-08-10
Debian Linux MEDIUM 5.5
CVE-2020-21676

A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS)…

Patch available
Fix from $1,600 2021-08-10
Libsixel MEDIUM 6.5
CVE-2020-21677

A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of …

Patch available
Fix from $1,600 2021-08-10
Fig2dev MEDIUM 5.5
CVE-2020-21680

A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via c…

Patch available
Fix from $1,600 2021-08-10
Webaccess\/scada CRITICAL 9.8
CVE-2021-32943

The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/…

Fix: 8.4.5 / 9.0.1+
Fix from $2,300 2021-08-10
Tivoli Workload Scheduler MEDIUM 5.3
CVE-2021-20349

IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could …

Mitigation only
Fix from $1,600 2021-08-09
Linux Kernel HIGH 7.8
CVE-2021-38166

In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a s…

Fix: 5.10.60 / 5.13.12+
Fix from $1,950 2021-08-07
A720r Firmware HIGH 7.5
CVE-2021-35325EPSS 13%

A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to cause a denial of service…

No fix yet
Fix from $1,950 2021-08-05
Gpac MEDIUM 5.5
CVE-2021-36584

An issue was discovered in GPAC 1.0.1. There is a heap-based buffer overflow in the function gp_rtp_builder_do_tx3g function in ietf/rtp_pck_3gpp.c, …

No fix yet
Fix from $1,600 2021-08-05
Firefox HIGH 8.8
CVE-2021-29970

A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered …

Fix: 78.12 / 90.0+
Fix from $1,950 2021-08-05
Firefox HIGH 8.8
CVE-2021-29976

Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory c…

Fix: 78.12 / 90.0+
Fix from $1,950 2021-08-05
Firefox HIGH 8.8
CVE-2021-29977

Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and we presume that wit…

Fix: 90.0+
Fix from $1,950 2021-08-05
Gpac MEDIUM 5.5
CVE-2020-24829

An issue was discovered in GPAC from v0.5.2 to v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_section_complet…

Fix: after 0.8.0
Fix from $1,600 2021-08-04
Fortisandbox HIGH 8.8
CVE-2021-26096

Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 may allow an authenticated attacker to manipulate …

Fix: 3.2.3+
Fix from $1,950 2021-08-04
Fortios HIGH 8.8
CVE-2021-24018

A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network …

Fix: 6.2.10 / 6.4.7+
Fix from $1,950 2021-08-04
Atomicparsley MEDIUM 5.5
CVE-2021-37231

A stack-buffer-overflow occurs in Atomicparsley 20210124.204813.840499f through APar_readX() in src/util.cpp while parsing a crafted mp4 file because…

Patch available
Fix from $1,600 2021-08-04
Atomicparsley CRITICAL 9.8
CVE-2021-37232

A stack overflow vulnerability occurs in Atomicparsley 20210124.204813.840499f through APar_read64() in src/util.cpp due to the lack of buffer size o…

Fix: after 20210124.204813.840499f
Fix from $2,300 2021-08-04