Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Foxit Studio Photo HIGH 7.8
CVE-2021-31437

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.931. User interaction is r…

Fix: after 3.6.6.933
Fix from $1,950 2021-04-29
Foxit Studio Photo HIGH 7.8
CVE-2021-31438

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.931. User interaction is r…

Fix: after 3.6.6.933
Fix from $1,950 2021-04-29
Binutils HIGH 7.8
CVE-2021-20294

A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a …

Fix: 2.35.2+
Fix from $1,950 2021-04-29
Mongooseos Mjs CRITICAL 9.8
CVE-2021-31875

In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse…

Patch available
Fix from $2,300 2021-04-29
P30 Firmware MEDIUM 6.5
CVE-2021-22327

There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient validation of the input file…

Mitigation only
Fix from $1,600 2021-04-28
P30 Firmware MEDIUM 6.5
CVE-2021-22330

There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthen…

Mitigation only
Fix from $1,600 2021-04-28
Cncsoft B HIGH 7.8
CVE-2021-22664

CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.

Fix: after 1.0.0.3
Fix from $1,950 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25035

Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25042

Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Altho…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Drawings Sdk HIGH 7.8
CVE-2021-31784

An out-of-bounds write vulnerability exists in the file-reading procedure in Open Design Alliance Drawings SDK before 2021.6 on all supported by ODA …

Fix: 10.4.1 / 2021.6+
Fix from $1,950 2021-04-26
Spectrum Protect Client MEDIUM 5.5
CVE-2021-20546

IBM Spectrum Protect Client 8.1.0.0 through 8.1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local atta…

Fix: after 8.1.11.0
Fix from $1,600 2021-04-26
Chrome HIGH 8.8
CVE-2021-21220 KEVEPSS 70%

Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corrup…

Fix: 89.0.4389.128+
Fix from $1,950 2021-04-26
Chrome MEDIUM 6.5
CVE-2021-21222

Heap buffer overflow in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to bypass site i…

Fix: 90.0.4430.85+
Fix from $1,600 2021-04-26
Chrome HIGH 8.8
CVE-2021-21225EPSS 7%

Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a craft…

Fix: 90.0.4430.85+
Fix from $1,950 2021-04-26
Spectrum Protect Client HIGH 7.8
CVE-2021-29672

IBM Spectrum Protect Client 8.1.0.0-8 through 1.11.0 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking when processi…

Fix: after 8.1.11.0
Fix from $1,950 2021-04-26
R7000 Firmware HIGH 8.8
CVE-2021-31802EPSS 14%

NETGEAR R7000 1.0.11.116 devices have a heap-based Buffer Overflow that is exploitable from the local network without authentication. The vulnerabili…

Fix: after 1.0.11.116
Fix from $1,950 2021-04-26
Pvrsrvkm.ko HIGH 7.0
CVE-2021-31795

The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allows attackers to overwrite hea…

Fix: after 2021-04-24
Fix from $1,950 2021-04-24
Debian Linux HIGH 7.5
CVE-2021-31598

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling while parsing crafted XML files,…

Patch available
Fix from $1,950 2021-04-24
Cscape HIGH 7.8
CVE-2021-22678

Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This could lead to memory corruptio…

Fix: 9.90+
Fix from $1,950 2021-04-23
Scalance X200 4p Irt Firmware CRITICAL 9.8
CVE-2021-25668

A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT…

Fix: 5.2.5 / 5.5.1+
Fix from $2,300 2021-04-22
Scalance X200 4p Irt Firmware CRITICAL 9.8
CVE-2021-25669

A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT…

Fix: 5.2.5 / 5.5.1+
Fix from $2,300 2021-04-22
Tecnomatix Robotexpert HIGH 7.8
CVE-2021-25670

A vulnerability has been identified in Tecnomatix RobotExpert (All versions < V16.1). Affected applications lack proper validation of user-supplied d…

Fix: 16.1+
Fix from $1,950 2021-04-22
Solid Edge Se2020 HIGH 7.8
CVE-2021-25678

A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (All versions < SE2020MP14), Solid Edge SE202…

Mitigation only
Fix from $1,950 2021-04-22
Solid Edge Se2020 HIGH 7.8
CVE-2021-27382

A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (All versions < SE2020MP14), Solid Edge SE202…

Mitigation only
Fix from $1,950 2021-04-22
Nucleus Net HIGH 8.1
CVE-2020-15795EPSS 6%

A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20)…

Fix: 5.2+
Fix from $1,950 2021-04-22
Nucleus Net HIGH 8.1
CVE-2020-27009EPSS 7%

A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20)…

Fix: 5.2+
Fix from $1,950 2021-04-22
Junos CRITICAL 9.8
CVE-2021-0254

A buffer size validation vulnerability in the overlayd service of Juniper Networks Junos OS may allow an unauthenticated remote attacker to send spec…

Mitigation only
Fix from $2,300 2021-04-22
Jhead HIGH 7.8
CVE-2021-3496

A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.

Patch available
Fix from $1,950 2021-04-22
Retdec CRITICAL 9.8
CVE-2020-23907

An issue was discovered in retdec v3.3. In function canSplitFunctionOn() of ir_modifications.cpp, there is a possible out of bounds read due to a hea…

Patch available
Fix from $2,300 2021-04-21
Gpac HIGH 7.8
CVE-2020-35979

An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buffer overflow in the function gp_rtp_builder_do_avc() in ietf/rtp_pck_…

Patch available
Fix from $1,950 2021-04-21