Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Fedora HIGH 7.1
CVE-2021-3561

An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted maliciou…

Patch available
Fix from $1,950 2021-05-26
Binutils HIGH 7.1
CVE-2021-3549

An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_l…

Patch available
Fix from $1,950 2021-05-26
Home Network Security HIGH 7.8
CVE-2021-32457

Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow a…

Fix: after 6.6.604
Fix from $1,950 2021-05-26
Linux Kernel HIGH 7.8
CVE-2020-27815

A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic th…

Fix: 4.9.249 / 4.14.213+
Fix from $1,950 2021-05-26
Trusted Firmware M MEDIUM 5.5
CVE-2021-27562 KEV

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when c…

Fix: after 1.2.0
Fix from $1,600 2021-05-25
Zephyr CRITICAL 9.8
CVE-2020-10064

Improper Input Frame Validation in ieee802154 Processing. Zephyr versions >= v1.14.2, >= v2.2.0 contain Stack-based Buffer Overflow (CWE-121), Heap-b…

Fix: after 2.2.0
Fix from $2,300 2021-05-25
Zephyr HIGH 8.8
CVE-2020-10065

Missing Size Checks in Bluetooth HCI over SPI. Zephyr versions >= v1.14.2, >= v2.2.0 contain Improper Handling of Length Parameter Inconsistency (CWE…

Fix: after 2.2.0
Fix from $1,950 2021-05-25
Zephyr HIGH 7.8
CVE-2020-13598

FS: Buffer Overflow when enabling Long File Names in FAT_FS and calling fs_stat. Zephyr versions >= v1.14.2, >= v2.3.0 contain Stack-based Buffer Ove…

Fix: after 2.3.0
Fix from $1,950 2021-05-25
Zephyr HIGH 7.6
CVE-2020-13600

Malformed SPI in response for eswifi can corrupt kernel memory. Zephyr versions >= 1.14.2, >= 2.3.0 contain Heap-based Buffer Overflow (CWE-122). For…

Fix: after 2.3.0
Fix from $1,950 2021-05-25
750 893 Firmware HIGH 7.5
CVE-2021-30186EPSS 7%

CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.

Mitigation only
Fix from $1,950 2021-05-25
750 893 Firmware CRITICAL 9.8
CVE-2021-30188

CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.

Mitigation only
Fix from $2,300 2021-05-25
750 893 Firmware CRITICAL 9.8
CVE-2021-30189

CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.

Mitigation only
Fix from $2,300 2021-05-25
750 893 Firmware CRITICAL 9.8
CVE-2021-30193

CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.

Mitigation only
Fix from $2,300 2021-05-25
Enterprise Linux CRITICAL 9.8
CVE-2018-25011

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.8
CVE-2020-36328

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check …

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Debian Linux HIGH 8.8
CVE-2021-31439

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authenticat…

Fix: 3.1.13 / 6.2.3-25426-3+
Fix from $1,950 2021-05-21
Phantompdf HIGH 7.8
CVE-2021-31473EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.3.37598. User interaction is requ…

Fix: after 10.1.3.37598
Fix from $1,950 2021-05-21
Jboss Core Services HIGH 8.6
CVE-2021-3517EPSS 8%

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be…

Fix: 2.9.11+
Fix from $1,950 2021-05-19
Routeros MEDIUM 6.5
CVE-2020-20266

Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/dot1x process. An authenticated remote at…

Fix: 6.47+
Fix from $1,600 2021-05-19
Routeros MEDIUM 6.5
CVE-2020-20227

Mikrotik RouterOs stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cau…

No fix yet
Fix from $1,600 2021-05-18
Routeros MEDIUM 6.5
CVE-2020-20245

Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the log process. An authenticated remote attacker can cause a Denia…

No fix yet
Fix from $1,600 2021-05-18
Routeros MEDIUM 6.5
CVE-2020-20246

Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the mactel process. An authenticated remote attacker can cause a De…

No fix yet
Fix from $1,600 2021-05-18
Telegram MEDIUM 5.5
CVE-2021-31315

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custo…

Fix: 7.1.0+
Fix from $1,600 2021-05-18
Telegram HIGH 7.1
CVE-2021-31320

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::generateGrad…

Fix: 7.1.0+
Fix from $1,950 2021-05-18
Telegram HIGH 7.1
CVE-2021-31321

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of…

Fix: 7.1.0+
Fix from $1,950 2021-05-18
Telegram MEDIUM 5.5
CVE-2021-31322

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate functi…

Fix: 7.1.0+
Fix from $1,600 2021-05-18
Telegram MEDIUM 5.5
CVE-2021-31323

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashP…

Fix: 7.1.0+
Fix from $1,600 2021-05-18
Routeros MEDIUM 6.5
CVE-2020-20236

Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attac…

No fix yet
Fix from $1,600 2021-05-18
Routeros MEDIUM 6.5
CVE-2020-20237

Mikrotik RouterOs 6.46.3 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attac…

No fix yet
Fix from $1,600 2021-05-18
Libredwg MEDIUM 5.5
CVE-2020-23861

A heap-based buffer overflow vulnerability exists in LibreDWG 0.10.1 via the read_system_page function at libredwg-0.10.1/src/decode_r2007.c:666:5, w…

Patch available
Fix from $1,600 2021-05-18