Vulnerability index

Browse CVEs

745 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
Unified Threat Management MEDIUM 6.5
CVE-2023-22897

An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi allows information disclosure of memory contents to…

Fix: 12.2.5.1+
Fix from $1,600 2023-04-12
Windows 10 1507 HIGH 8.8
CVE-2023-24886

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

Fix: 10.0.10240.19869 / 10.0.14393.5850+
Fix from $1,950 2023-04-11
Opensips HIGH 7.5
CVE-2023-27598

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Prior to versions 3.1.7 and 3.2.4, sending a malformed `Via` header to OpenSIP…

Fix: 3.1.7 / 3.2.4+
Fix from $1,950 2023-03-15
Windows 10 1507 HIGH 8.8
CVE-2023-23413

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

Fix: 10.0.10240.19805 / 10.0.14393.5786+
Fix from $1,950 2023-03-14
Hyperkit HIGH 7.8
CVE-2021-32846

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vtsock_proc_tx` in `virtio-sock`…

Fix: after 0.20210107
Fix from $1,950 2023-02-17
Hyperkit HIGH 7.8
CVE-2021-32845

HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, the implementation of `q…

Fix: after 0.20210107
Fix from $1,950 2023-02-17
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2023-22281

On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP A…

Fix: 14.1.5.3 / 15.1.8+
Fix from $1,950 2023-02-01
Dynamips HIGH 7.5
CVE-2022-47012

Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.

No fix yet
Fix from $1,950 2023-01-20
Windows 10 MEDIUM 5.5
CVE-2023-21753

Event Tracing for Windows Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2023-01-10
Firefox HIGH 8.8
CVE-2022-31741

A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulne…

Fix: 91.10 / 101+
Fix from $1,950 2022-12-22
Sftpserver CRITICAL 9.8
CVE-2020-36617

A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is the function sftp_parse_path o…

Fix: 2+
Fix from $2,300 2022-12-18
Hyperview Player HIGH 7.8
CVE-2022-2949

Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A…

Fix: after 2021.1.0.27
Fix from $1,950 2022-12-13
Hyperview Player HIGH 7.8
CVE-2022-2950

Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A…

Fix: after 2021.1.0.27
Fix from $1,950 2022-12-13
Android MEDIUM 6.7
CVE-2022-32615

In ccd, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution pri…

Mitigation only
Fix from $1,600 2022-11-08
Android MEDIUM 6.7
CVE-2022-32616

In isp, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution pri…

Mitigation only
Fix from $1,600 2022-11-08
Fedora HIGH 7.5
CVE-2022-39282

FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using `/parallel` command line switch might read…

Fix: 2.8.1+
Fix from $1,950 2022-10-12
Fedora HIGH 7.5
CVE-2022-39283

FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read unini…

Fix: 2.8.1+
Fix from $1,950 2022-10-12
Alienware Area 51 R5 Firmware HIGH 7.8
CVE-2022-34390

Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by …

Fix: 2.0.6+
Fix from $1,950 2022-10-12
Linux Kernel MEDIUM 5.5
CVE-2022-40768

drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecomman…

Fix: after 5.19.9
Fix from $1,600 2022-09-18
Scylla HIGH 8.1
CVE-2022-29240

Scylla is a real-time big data database that is API-compatible with Apache Cassandra and Amazon DynamoDB. When decompressing CQL frame received from …

Fix: 4.6.7 / 5.0.3+
Fix from $1,950 2022-09-15
Linux Kernel MEDIUM 6.5
CVE-2022-2308

A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in…

Mitigation only
Fix from $1,600 2022-09-01
Samba HIGH 8.1
CVE-2022-32745

A flaw was found in Samba. Samba AD users can cause the server to access uninitialized data with an LDAP add or modify the request, usually resulting…

Fix: 4.14.14 / 4.15.9+
Fix from $1,950 2022-08-25
Android MEDIUM 5.5
CVE-2021-0698

In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information di…

Mitigation only
Fix from $1,600 2022-08-24
Android MEDIUM 5.5
CVE-2021-0887

In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This could lead to local information…

Mitigation only
Fix from $1,600 2022-08-24
Crow HIGH 7.5
CVE-2022-38668

HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfilling a reque…

Patch available
Fix from $1,950 2022-08-22
Radare2 HIGH 7.5
CVE-2020-27795

A segmentation fault was discovered in radare2 with adf command. In libr/core/cmd_anal.c, when command "adf" has no or wrong argument, anal_fcn_data …

Fix: 4.4.0+
Fix from $1,950 2022-08-19
Android MEDIUM 5.5
CVE-2022-20357

In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information di…

Patch available
Fix from $1,600 2022-08-10
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-34655

In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing the HTTP::payload command is co…

Fix: 14.1.5 / 15.1.6.1+
Fix from $1,950 2022-08-04
Nbiot Sdk CRITICAL 9.8
CVE-2022-26437

In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additiona…

Mitigation only
Fix from $2,300 2022-08-01
Libtiff MEDIUM 5.5
CVE-2022-34266

The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (application crash), a different v…

Mitigation only
Fix from $1,600 2022-07-19