Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Tensorflow HIGH 7.8
CVE-2021-29558

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.SparseSplit`. This…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.1
CVE-2021-29560

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `tf.raw_ops.RaggedTensorToTens…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29566

TensorFlow is an end-to-end open source platform for machine learning. An attacker can write outside the bounds of heap allocated arrays by passing i…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29571

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.MaxPoolGradWithArgmax` can cause reads outsi…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29535

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedMul` by passing in i…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29536

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedReshape` by passing …

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29537

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow in `QuantizedResizeBilinear` by p…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29540

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow to occur in `Conv2DBackpropFilter…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29542

TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a heap buffer overflow by passing crafted inputs to `tf.…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29514

TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does not specify a valid `SparseT…

Fix: 2.3.3 / 2.4.2+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29520

TensorFlow is an end-to-end open source platform for machine learning. Missing validation between arguments to `tf.raw_ops.Conv3DBackprop*` operation…

Fix: 2.1.4 / 2.2.3+
Fix from $1,950 2021-05-14
Tensorflow HIGH 7.8
CVE-2021-29512

TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does not specify a valid `SparseT…

Fix: 2.3.3 / 2.4.2+
Fix from $1,950 2021-05-14
Hermes CRITICAL 9.8
CVE-2021-23909

An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MCU allows remote code executio…

No fix yet
Fix from $2,300 2021-05-13
Hermes CRITICAL 9.8
CVE-2021-23910

An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. There is an out-of-bounds array access …

No fix yet
Fix from $2,300 2021-05-13
Cx One HIGH 7.8
CVE-2021-27413EPSS 10%

Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based buffer overflow, which may all…

Fix: after 5.0.29
Fix from $1,950 2021-05-13
Enterprise Linux MEDIUM 6.0
CVE-2021-20221

An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64…

Fix: after 4.2.0
Fix from $1,600 2021-05-13
Fedora HIGH 7.8
CVE-2020-27823

A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. T…

Fix: 2.4.0+
Fix from $1,950 2021-05-13
Evm MEDIUM 6.5
CVE-2021-29511

evm is a pure Rust implementation of Ethereum Virtual Machine. Prior to the patch, when executing specific EVM opcodes related to memory operations t…

Fix: after 0.21.0
Fix from $1,600 2021-05-12
Debian Linux HIGH 7.5
CVE-2021-20277

A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a…

Fix: 4.12.13 / 4.13.6+
Fix from $1,950 2021-05-12
Tecnomatix Plant Simulation HIGH 7.8
CVE-2021-27397

A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V16.0.5). The PlantSimCore.dll library lacks proper validation of …

Fix: 16.0.5+
Fix from $1,950 2021-05-12
Simatic Hmi Ktp Mobile Panels Firmware MEDIUM 5.3
CVE-2019-19276

A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI K…

Patch available
Fix from $1,600 2021-05-12
Web Media Extensions HIGH 7.8
CVE-2021-28465

Web Media Extensions Remote Code Execution Vulnerability

Patch available
Fix from $1,950 2021-05-11
Routeros MEDIUM 6.5
CVE-2020-20265

Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /ram/pckg/wireless/nova/bin/wireless process. An au…

Fix: 6.47+
Fix from $1,600 2021-05-11
Routeros MEDIUM 6.5
CVE-2020-20267

Mikrotik RouterOs before 6.47 (stable tree) suffers from a memory corruption vulnerability in the /nova/bin/resolver process. An authenticated remote…

Fix: 6.47+
Fix from $1,600 2021-05-11
Openscad HIGH 7.8
CVE-2020-28600

An out-of-bounds write vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL…

No fix yet
Fix from $1,950 2021-05-10
Bifrost Gpu Kernel Driver HIGH 8.8
CVE-2021-28664 KEVEPSS 5%

The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/w…

Mitigation only
Fix from $1,950 2021-05-10
Cncsoft Screeneditor HIGH 7.8
CVE-2021-22672EPSS 10%

Delta Electronics' CNCSoft ScreenEditor in versions prior to v1.01.30 could allow the corruption of data, a denial-of-service condition, or code exec…

Fix: 1.01.30+
Fix from $1,950 2021-05-10
Ac11 Firmware CRITICAL 9.8
CVE-2021-31755 KEVEPSS 87%

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows a…

Fix: after 02.03.01.104_cn
Fix from $2,300 2021-05-07
Ac11 Firmware CRITICAL 9.8
CVE-2021-31756

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /gofrom/setwanType allo…

Fix: after 02.03.01.104_cn
Fix from $2,300 2021-05-07
Ac11 Firmware CRITICAL 9.8
CVE-2021-31757

An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setVLAN allows …

Fix: after 02.03.01.104_cn
Fix from $2,300 2021-05-07