Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Chrome HIGH 8.8
CVE-2021-21143

Heap buffer overflow in Extensions in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension …

Fix: 88.0.4324.146+
Fix from $1,950 2021-02-09
Chrome HIGH 8.8
CVE-2021-21144

Heap buffer overflow in Tab Groups in Google Chrome prior to 88.0.4324.146 allowed an attacker who convinced a user to install a malicious extension …

Fix: 88.0.4324.146+
Fix from $1,950 2021-02-09
Chrome HIGH 8.8
CVE-2021-21128EPSS 7%

Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted H…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,950 2021-02-09
Chrome HIGH 8.8
CVE-2020-16044

Use after free in WebRTC in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP p…

Fix: 88.0.4324.96+
Fix from $1,950 2021-02-09
Fedora MEDIUM 6.5
CVE-2020-36151

Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and over…

Fix: after 1.1
Fix from $1,600 2021-02-08
Ezxml HIGH 8.1
CVE-2021-26220

The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.

Fix: after 0.8.6
Fix from $1,950 2021-02-08
Ezxml HIGH 8.1
CVE-2021-26221

The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.

Fix: after 0.8.6
Fix from $1,950 2021-02-08
Ezxml HIGH 8.1
CVE-2021-26222

The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the memory pool.

Fix: after 0.8.6
Fix from $1,950 2021-02-08
Mongoose CRITICAL 9.1
CVE-2021-26528

The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connection request after exhausting …

No fix yet
Fix from $2,300 2021-02-08
Mongoose CRITICAL 9.1
CVE-2021-26529

The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable to remote OOB write attack v…

Fix: after 6.18
Fix from $2,300 2021-02-08
Mongoose CRITICAL 9.1
CVE-2021-26530

The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OOB write attack via connection…

No fix yet
Fix from $2,300 2021-02-08
Godot Engine HIGH 7.8
CVE-2021-26826

A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the co…

Fix: after 3.2
Fix from $1,950 2021-02-08
Cryptography CRITICAL 9.1
CVE-2020-36242EPSS 7%

In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an in…

Fix: 3.3.2+
Fix from $2,300 2021-02-07
Gitea HIGH 7.5
CVE-2021-3382

Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to…

Fix: after 1.13.1
Fix from $1,950 2021-02-05
Apex One HIGH 7.8
CVE-2021-25249

An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Se…

Patch available
Fix from $1,950 2021-02-04
Android MEDIUM 6.7
CVE-2021-0343

In kisd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executio…

Mitigation only
Fix from $1,600 2021-02-04
Android MEDIUM 6.7
CVE-2021-0346

In vpu, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execut…

Mitigation only
Fix from $1,600 2021-02-04
Android MEDIUM 6.7
CVE-2021-0348

In vpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…

Mitigation only
Fix from $1,600 2021-02-04
Rv016 Multi Wan Vpn Router Firmware HIGH 7.2
CVE-2021-1335

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…

Fix: after 4.2.3.14
Fix from $1,950 2021-02-04
Rv016 Multi Wan Vpn Router Firmware HIGH 7.2
CVE-2021-1337

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…

Fix: after 4.2.3.14
Fix from $1,950 2021-02-04
Rv016 Multi Wan Vpn Router Firmware HIGH 7.2
CVE-2021-1323

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could al…

Fix: after 4.2.3.14
Fix from $1,950 2021-02-04
Planmaker 2021 HIGH 7.8
CVE-2020-13586

A memory corruption vulnerability exists in the Excel Document SST Record 0x00fc functionality of SoftMaker Software GmbH SoftMaker Office PlanMaker …

No fix yet
Fix from $1,950 2021-02-04
Planmaker 2021 HIGH 7.8
CVE-2020-27247

A specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…

Mitigation only
Fix from $1,950 2021-02-04
Planmaker 2021 HIGH 7.8
CVE-2020-27248

A specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…

Mitigation only
Fix from $1,950 2021-02-04
Planmaker 2021 HIGH 7.8
CVE-2020-27249

A specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…

Mitigation only
Fix from $1,950 2021-02-04
Planmaker 2021 HIGH 7.8
CVE-2020-13579EPSS 73%

An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application…

No fix yet
Fix from $1,950 2021-02-04
Planmaker 2021 HIGH 7.8
CVE-2020-13580EPSS 73%

An exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker a…

No fix yet
Fix from $1,950 2021-02-04
Rtl8195a Firmware HIGH 8.1
CVE-2020-25855

The function AES_UnWRAP() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate …

Fix: 2.08+
Fix from $1,950 2021-02-03
Rtl8195a Firmware HIGH 8.1
CVE-2020-25856

The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not valid…

Fix: 2.08+
Fix from $1,950 2021-02-03
Rtl8195a Firmware HIGH 7.5
CVE-2020-25857

The function ClientEAPOLKeyRecvd() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not …

Fix: 2.08+
Fix from $1,950 2021-02-03