Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22751

A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of informatio…

Fix: after 15.0.0.21140
Fix from $1,950 2021-06-11
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22752

A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote c…

Fix: after 15.0.0.21140
Fix from $1,950 2021-06-11
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22754

A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote c…

Fix: after 15.0.0.21140
Fix from $1,950 2021-06-11
Interactive Graphical Scada System HIGH 7.8
CVE-2021-22755

A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of informatio…

Fix: after 15.0.0.21140
Fix from $1,950 2021-06-11
Android MEDIUM 6.7
CVE-2021-25396

An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write and code execution.

Mitigation only
Fix from $1,600 2021-06-11
Android HIGH 7.8
CVE-2021-25407

A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.

No fix yet
Fix from $1,950 2021-06-11
Android HIGH 7.8
CVE-2021-25408

A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code execution.

Mitigation only
Fix from $1,950 2021-06-11
Android CRITICAL 9.8
CVE-2021-25384

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor library prior to SMR MAY-2021 Rele…

Mitigation only
Fix from $2,300 2021-06-11
Jerryscript CRITICAL 9.8
CVE-2020-23321

There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.

Patch available
Fix from $2,300 2021-06-10
Jerryscript CRITICAL 9.8
CVE-2020-23323

There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0.

Patch available
Fix from $2,300 2021-06-10
Jerryscript HIGH 8.8
CVE-2021-26195

An issue was discovered in JerryScript 2.4.0. There is a heap-buffer-overflow in lexer_parse_number in js-lexer.c file.

Patch available
Fix from $1,950 2021-06-10
Jerryscript CRITICAL 9.8
CVE-2020-23303

There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.

Patch available
Fix from $2,300 2021-06-10
Jerryscript CRITICAL 9.8
CVE-2020-23306

There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.

Patch available
Fix from $2,300 2021-06-10
HTTP Server HIGH 7.3
CVE-2020-35452EPSS 53%

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of thi…

Fix: after 2.4.46
Fix from $1,950 2021-06-10
HTTP Server CRITICAL 9.8
CVE-2021-26691EPSS 68%

In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a heap overflow

Fix: 18.1.0.1.0+
Fix from $2,300 2021-06-10
Baseboard Management Controller Firmware HIGH 7.8
CVE-2020-24473

Out of bounds write in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an…

Fix: 2.48.ce3e3bd2+
Fix from $1,950 2021-06-09
Efi Bios 7215 MEDIUM 6.5
CVE-2021-0113

Out of bounds write in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated…

Mitigation only
Fix from $1,600 2021-06-09
Jhl6240 Thunderbolt 3 Firmware MEDIUM 5.5
CVE-2020-12289

Out-of-bounds write in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local ac…

Fix: 21 / 22+
Fix from $1,600 2021-06-09
Debian Linux CRITICAL 9.8
CVE-2021-33833

ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A …

Fix: after 1.39
Fix from $2,300 2021-06-09
Netweaver Abap HIGH 7.5
CVE-2021-27633

SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7…

Mitigation only
Fix from $1,950 2021-06-09
Netweaver Abap MEDIUM 5.9
CVE-2021-27634

SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7…

Mitigation only
Fix from $1,600 2021-06-09
Getsusp HIGH 7.8
CVE-2021-31837

Memory corruption vulnerability in the driver file component in McAfee GetSusp prior to 4.0.0 could allow a program being investigated on the local m…

Fix: 4.0.0+
Fix from $1,950 2021-06-09
Netweaver As Internet Graphics Server MEDIUM 5.9
CVE-2021-27620

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system sta…

Mitigation only
Fix from $1,600 2021-06-09
Netweaver As Internet Graphics Server MEDIUM 5.9
CVE-2021-27622

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system sta…

Mitigation only
Fix from $1,600 2021-06-09
Netweaver As Internet Graphics Server MEDIUM 5.9
CVE-2021-27623

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system sta…

Mitigation only
Fix from $1,600 2021-06-09
Netweaver As Internet Graphics Server MEDIUM 5.9
CVE-2021-27624

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system sta…

Mitigation only
Fix from $1,600 2021-06-09
Netweaver As Internet Graphics Server MEDIUM 5.9
CVE-2021-27625

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system sta…

Mitigation only
Fix from $1,600 2021-06-09
Netweaver As Internet Graphics Server MEDIUM 5.9
CVE-2021-27626

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system sta…

Mitigation only
Fix from $1,600 2021-06-09
Netweaver As Internet Graphics Server MEDIUM 5.9
CVE-2021-27627

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system sta…

Mitigation only
Fix from $1,600 2021-06-09
Netweaver As Abap HIGH 7.5
CVE-2021-27628

SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49…

Mitigation only
Fix from $1,950 2021-06-09