Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Android HIGH 7.8
CVE-2021-0464

In sound_trigger_event_alloc of platform.h, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalatio…

Mitigation only
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0465

In GenerateFaceMask of face.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of priv…

Mitigation only
Fix from $1,950 2021-03-10
Android HIGH 7.8
CVE-2021-0393

In Scanner::LiteralBuffer::NewCapacity of scanner.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote c…

Mitigation only
Fix from $1,950 2021-03-10
Android CRITICAL 9.8
CVE-2021-0396

In Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds write due to an incorrect bo…

Mitigation only
Fix from $2,300 2021-03-10
Android MEDIUM 6.7
CVE-2021-0370

In Write of NxpMfcReader.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Patch available
Fix from $1,600 2021-03-10
Hhvm CRITICAL 9.8
CVE-2020-1916

An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write…

Fix: 4.56.2 / 4.78.1+
Fix from $2,300 2021-03-10
Hhvm CRITICAL 9.8
CVE-2020-1917

xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated string, but was not using its stan…

Fix: 4.56.3 / 4.80.2+
Fix from $2,300 2021-03-10
Hhvm HIGH 7.5
CVE-2020-1921

In the crypt function, we attempt to null terminate a buffer using the size of the input salt without validating that the offset is within the buffer…

Fix: 4.56.3 / 4.80.2+
Fix from $1,950 2021-03-10
Debian Linux HIGH 7.8
CVE-2020-35524

A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can l…

Fix: 4.2.0+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21169

Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially perform out of bounds memory access…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21160

Heap buffer overflow in WebAudio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Chrome HIGH 8.8
CVE-2021-21161

Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Linux Kernel HIGH 7.8
CVE-2021-27365

An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and c…

Fix: 4.4.260 / 4.9.260+
Fix from $1,950 2021-03-07
Jpeg Xl HIGH 7.8
CVE-2021-28026

jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicous jxl file using djxl, an att…

No fix yet
Fix from $1,950 2021-03-05
Android CRITICAL 9.8
CVE-2021-25346

A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.

Mitigation only
Fix from $2,300 2021-03-04
Enterprise Linux HIGH 7.8
CVE-2021-3404

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a h…

No fix yet
Fix from $1,950 2021-03-04
Enterprise Linux HIGH 8.2
CVE-2021-20233

A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption tha…

Fix: 2.06+
Fix from $1,950 2021-03-03
Fvdesigner HIGH 7.8
CVE-2021-22666

Fatek FvDesigner Version 1.5.76 and prior is vulnerable to a stack-based buffer overflow while project files are being processed, allowing an attacke…

Fix: after 1.5.76
Fix from $1,950 2021-03-03
Fvdesigner HIGH 7.8
CVE-2021-22683

Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a spe…

Fix: after 1.5.76
Fix from $1,950 2021-03-03
Enterprise Linux HIGH 7.6
CVE-2020-25647

A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assu…

Fix: 2.06+
Fix from $1,950 2021-03-03
Enterprise Linux MEDIUM 6.7
CVE-2020-27749

A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variab…

Fix: 2.06+
Fix from $1,600 2021-03-03
Enterprise Linux MEDIUM 6.7
CVE-2021-20225

A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling…

Fix: 2.06+
Fix from $1,600 2021-03-03
Libjxl CRITICAL 9.8
CVE-2021-27804

JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption.

Fix: after 0.3.2
Fix from $2,300 2021-03-02
Document Server CRITICAL 9.8
CVE-2021-25832EPSS 13%

A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using th…

Fix: after 6.0.0
Fix from $2,300 2021-03-01
Diskstation Manager HIGH 8.1
CVE-2021-26562

Out-of-bounds write vulnerability in synoagentregisterd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows man-in-the-middle attackers…

Fix: 6.2.3-25426-3+
Fix from $1,950 2021-02-26
Diskstation Manager HIGH 7.8
CVE-2021-26567

Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute arbitrary code via filename and…

Fix: 2.2.7.1 / 6.2.3-25426-3+
Fix from $1,950 2021-02-26
Barcode Generator HIGH 7.5
CVE-2021-27799

ean_leading_zeroes in backend/upcean.c in Zint Barcode Generator 2.9.1 has a stack-based buffer overflow that is reachable from the C API through an …

Patch available
Fix from $1,950 2021-02-26
Android MEDIUM 6.7
CVE-2021-0402

In jpeg, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execu…

Mitigation only
Fix from $1,600 2021-02-26
Android MEDIUM 6.7
CVE-2021-0405

In performance driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with S…

Mitigation only
Fix from $1,600 2021-02-26
Android MEDIUM 6.7
CVE-2021-0406

In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System exe…

Mitigation only
Fix from $1,600 2021-02-26