Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Debian Linux HIGH 7.8
CVE-2019-25051

objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config…

Patch available
Fix from $1,950 2021-07-20
Matio HIGH 8.8
CVE-2020-36428

matio (aka MAT File I/O Library) 1.5.18 through 1.5.21 has a heap-based buffer overflow in ReadInt32DataDouble (called from ReadInt32Data and Mat_Var…

Fix: after 1.5.21
Fix from $1,950 2021-07-20
Open62541 MEDIUM 5.5
CVE-2020-36429

Variant_encodeJson in open62541 1.x before 1.0.4 has an out-of-bounds write for a large recursion depth.

Fix: 1.0.4+
Fix from $1,600 2021-07-20
Fedora HIGH 7.8
CVE-2020-36430

libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer dat…

Fix: 0.15.1+
Fix from $1,950 2021-07-20
Unicorn Engine MEDIUM 5.5
CVE-2020-36431

Unicorn Engine 1.0.2 has an out-of-bounds write in helper_wfe_arm.

Patch available
Fix from $1,600 2021-07-20
Matio MEDIUM 6.5
CVE-2021-36977

matio (aka MAT File I/O Library) 1.5.20 and 1.5.21 has a heap-based buffer overflow in H5MM_memcpy (called from H5MM_malloc and H5C_load_entry), rela…

Patch available
Fix from $1,600 2021-07-20
Routeros MEDIUM 6.5
CVE-2020-20249

Mikrotik RouterOs before stable 6.47 suffers from a memory corruption vulnerability in the resolver process. By sending a crafted packet, an authenti…

Fix: 6.47+
Fix from $1,600 2021-07-19
Manageengine Assetexplorer HIGH 7.5
CVE-2021-20109

Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the …

Mitigation only
Fix from $1,950 2021-07-19
Windows 10 1507 MEDIUM 6.8
CVE-2021-34448 KEVEPSS 40%

Scripting Engine Memory Corruption Vulnerability

Fix: 10.0.10240.19003 / 10.0.14393.4530+
Fix from $1,600 2021-07-16
Ok File Formats MEDIUM 6.5
CVE-2020-23706

A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-file-formats through 2020-06-26 …

Fix: after 2020-06-26
Fix from $1,600 2021-07-15
Ok File Formats MEDIUM 6.5
CVE-2020-23707

A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file-formats through 2020-06-26 a…

Fix: after 2020-06-26
Fix from $1,600 2021-07-15
Steel Belted Radius Carrier CRITICAL 9.8
CVE-2021-0276

A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, …

Mitigation only
Fix from $2,300 2021-07-15
Client Connector CRITICAL 9.8
CVE-2020-11633

The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversa…

Fix: 2.1.2.81+
Fix from $2,300 2021-07-15
Radare2 Extras CRITICAL 9.8
CVE-2020-24133

A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary c…

Fix: 5.1.0+
Fix from $2,300 2021-07-14
Serv U CRITICAL 10.0
CVE-2021-35211 KEVEPSS 91%

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If …

Fix: 15.2.3+
Fix from $2,300 2021-07-14
Routeros MEDIUM 6.5
CVE-2020-20231

Mikrotik RouterOs through stable version 6.48.3 suffers from a memory corruption vulnerability in the /nova/bin/detnet process. An authenticated remo…

Fix: after 6.48.3
Fix from $1,600 2021-07-14
Android CRITICAL 9.8
CVE-2021-0515

In Factory::CreateStrictFunctionMap of factory.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remot…

Mitigation only
Fix from $2,300 2021-07-14
Android HIGH 7.8
CVE-2021-0577

In flv extractor, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no add…

Mitigation only
Fix from $1,950 2021-07-14
Android MEDIUM 6.7
CVE-2021-0585

In beginWrite and beginRead of MessageQueueBase.h, there is a possible out of bounds write due to improper input validation. This could lead to local…

Mitigation only
Fix from $1,600 2021-07-14
Android HIGH 7.8
CVE-2021-0587

In StreamOut::prepareForWriting of StreamOut.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalatio…

Mitigation only
Fix from $1,950 2021-07-14
Android HIGH 7.8
CVE-2021-0589

In BTM_TryAllocateSCN of btm_scn.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of…

Mitigation only
Fix from $1,950 2021-07-14
Android HIGH 8.8
CVE-2021-0592

In various functions in WideVine, there are possible out of bounds writes due to improper input validation. This could lead to remote code execution …

Mitigation only
Fix from $1,950 2021-07-14
Android MEDIUM 5.5
CVE-2021-0601

In encodeFrames of avc_enc_fuzzer.cpp, there is a possible out of bounds write due to a double free. This could lead to local information disclosure …

Mitigation only
Fix from $1,600 2021-07-14
Netweaver Abap MEDIUM 5.3
CVE-2021-33684

SAP NetWeaver AS ABAP and ABAP Platform, versions - KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64NUC 7.21, 7.…

Mitigation only
Fix from $1,600 2021-07-14
3d Visual Enterprise Viewer MEDIUM 6.5
CVE-2021-33681

SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated CGM file received from untrusted sources which causes out of bounds w…

Mitigation only
Fix from $1,600 2021-07-14
Bento4 MEDIUM 6.5
CVE-2020-19721

A heap buffer overflow vulnerability in Ap4TrunAtom.cpp of Bento 1.5.1-628 may lead to an out-of-bounds write while running mp42aac, leading to syste…

No fix yet
Fix from $1,600 2021-07-13
Routeros MEDIUM 6.5
CVE-2020-20252

Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote…

Fix: 6.47+
Fix from $1,600 2021-07-13
Jsish HIGH 7.5
CVE-2020-22907

Stack overflow vulnerability in function jsi_evalcode_sub in jsish before 3.0.18, allows remote attackers to cause a Denial of Service via a crafted …

Fix: 3.0.18+
Fix from $1,950 2021-07-13
Routeros MEDIUM 6.5
CVE-2020-20250

Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote…

Fix: 6.47+
Fix from $1,600 2021-07-13
Jt2go HIGH 7.8
CVE-2021-34327

A vulnerability has been identified in JT2Go (All versions < V13.2), Solid Edge SE2021 (All Versions < SE2021MP5), Teamcenter Visualization (All vers…

Fix: 13.2.0+
Fix from $1,950 2021-07-13