Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Substance 3d Stager HIGH 7.8
CVE-2024-45139

Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execut…

Fix: 3.0.4+
Fix from $1,950 2024-10-09
Animate HIGH 7.8
CVE-2024-47417

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution …

Fix: 23.0.8 / 24.0.5+
Fix from $1,950 2024-10-09
Animate HIGH 7.8
CVE-2024-47410

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution…

Fix: 23.0.8 / 24.0.5+
Fix from $1,950 2024-10-09
Dimension HIGH 7.8
CVE-2024-45150

Dimension versions 4.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex…

Fix: 4.0.4+
Fix from $1,950 2024-10-09
Hdf5 CRITICAL 9.8
CVE-2024-32608

HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service …

Fix: 1.14.4+
Fix from $2,300 2024-10-09
Tecnomatix Plant Simulation HIGH 7.8
CVE-2024-45471

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14…

Fix: 2302.0016 / 2404.0005+
Fix from $1,950 2024-10-08
Tecnomatix Plant Simulation HIGH 7.8
CVE-2024-45469

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14…

Fix: 2302.0016 / 2404.0005+
Fix from $1,950 2024-10-08
Tecnomatix Plant Simulation HIGH 7.8
CVE-2024-45470

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14…

Fix: 2302.0016 / 2404.0005+
Fix from $1,950 2024-10-08
Jt2go HIGH 7.8
CVE-2024-41902

A vulnerability has been identified in JT2Go (All versions < V2406.0003). The affected application contains a stack-based buffer overflow vulnerabili…

Fix: 2406.0003+
Fix from $1,950 2024-10-08
Android HIGH 8.8
CVE-2024-34669

Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code wi…

Mitigation only
Fix from $1,950 2024-10-08
Android HIGH 8.8
CVE-2024-34665

Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code wit…

Mitigation only
Fix from $1,950 2024-10-08
Android HIGH 8.8
CVE-2024-34666

Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute…

Mitigation only
Fix from $1,950 2024-10-08
Android HIGH 8.8
CVE-2024-34667

Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code wit…

Mitigation only
Fix from $1,950 2024-10-08
Android HIGH 8.8
CVE-2024-34668

Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code wit…

Mitigation only
Fix from $1,950 2024-10-08
Openharmony MEDIUM 5.5
CVE-2024-45382

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.

Fix: after 4.1.0
Fix from $1,600 2024-10-08
Wsa8835 Firmware MEDIUM 6.7
CVE-2024-23374

Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.

Mitigation only
Fix from $1,600 2024-10-07
Yocto MEDIUM 6.7
CVE-2024-20098

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executi…

Mitigation only
Fix from $1,600 2024-10-07
Yocto MEDIUM 6.7
CVE-2024-20099

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executi…

Mitigation only
Fix from $1,600 2024-10-07
Iot Yocto CRITICAL 9.8
CVE-2024-20100

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional…

Fix: after 3.3
Fix from $2,300 2024-10-07
Software Development Kit CRITICAL 9.8
CVE-2024-20101

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional…

Fix: after 3.3
Fix from $2,300 2024-10-07
Software Development Kit CRITICAL 9.8
CVE-2024-20103

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no addition…

Fix: after 3.3
Fix from $2,300 2024-10-07
Android MEDIUM 6.7
CVE-2024-20090

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executio…

Mitigation only
Fix from $1,600 2024-10-07
Android HIGH 7.8
CVE-2024-20092

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System executio…

Mitigation only
Fix from $1,950 2024-10-07
Antivirus MEDIUM 5.5
CVE-2024-9481

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed eml file t…

Fix: 24092400+
Fix from $1,600 2024-10-04
Antivirus MEDIUM 5.5
CVE-2024-9482

An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS allows a malformed Mach-O fil…

Fix: 24092400+
Fix from $1,600 2024-10-04
Zephyr MEDIUM 6.5
CVE-2024-6444

No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.

Fix: after 3.6.0
Fix from $1,600 2024-10-04
Zephyr MEDIUM 6.5
CVE-2024-6443

In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.

Fix: after 3.6.0
Fix from $1,600 2024-10-04
Zephyr MEDIUM 6.5
CVE-2024-6442

In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.

Fix: after 3.6.0
Fix from $1,600 2024-10-04
Vigor3912 Firmware CRITICAL 9.8
CVE-2024-41593

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-ext…

Fix: 4.2.7 / 4.3.2.8+
Fix from $2,300 2024-10-03
Vigor3910 Firmware HIGH 8.0
CVE-2024-41595

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bo…

Fix: after 4.3.2.6
Fix from $1,950 2024-10-03