Vulnerability index

Browse CVEs

745 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
Debian Linux HIGH 8.8
CVE-2022-35414

softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE…

Fix: after 7.0.0
Fix from $1,950 2022-07-11
Gpac MEDIUM 5.5
CVE-2021-40608

The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box command.

Fix: 2.0.0+
Fix from $1,600 2022-06-28
Opus HIGH 7.5
CVE-2022-25345

All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non…

No fix yet
Fix from $1,950 2022-06-17
Trilogy HIGH 7.5
CVE-2022-31026

Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authentication packet, causing the cl…

Fix: 2.1.1+
Fix from $1,950 2022-06-09
Tensorflow MEDIUM 5.5
CVE-2022-29205

TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, there is a potential for segfault / den…

Fix: 2.6.4 / 2.7.2+
Fix from $1,600 2022-05-20
Android MEDIUM 5.5
CVE-2022-20119

In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This could lead to local informat…

Mitigation only
Fix from $1,600 2022-05-10
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-26370

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Pro…

Mitigation only
Fix from $1,950 2022-05-05
Libwav HIGH 7.5
CVE-2022-28488

The function wav_format_write in libwav.c in libwav through 2017-04-20 has an Use of Uninitialized Variable vulnerability.

Fix: after 2017-04-20
Fix from $1,950 2022-05-04
Openj9 MEDIUM 5.3
CVE-2021-41041

In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered…

Fix: 0.32.0+
Fix from $1,600 2022-04-27
Linux Kernel MEDIUM 5.5
CVE-2022-0433

A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_next_key function of the BPF blo…

Fix: after 5.16
Fix from $1,600 2022-03-10
Simplelink Cc32xx Software Development Kit MEDIUM 5.3
CVE-2021-21966

An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.…

Fix: 1.0.1.15-2.15.0.1 / 5.30.00.08+
Fix from $1,600 2022-02-16
Chrome HIGH 8.8
CVE-2022-0115

Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via…

Fix: 97.0.4692.71+
Fix from $1,950 2022-02-12
Android MEDIUM 6.5
CVE-2021-39671

In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to information dis…

Patch available
Fix from $1,600 2022-02-11
Tensorflow HIGH 8.8
CVE-2022-23573

Tensorflow is an Open Source Machine Learning Framework. The implementation of `AssignOp` can result in copying uninitialized data to a new tensor. T…

Fix: after 2.6.2
Fix from $1,950 2022-02-04
H2o MEDIUM 5.9
CVE-2021-43848

h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may attempt to access uninitialized memory. When receiving QUIC frames i…

Fix: 2021-12-20+
Fix from $1,600 2022-02-01
Columnar CRITICAL 9.8
CVE-2021-45685

An issue was discovered in the columnar crate through 2021-01-07 for Rust. ColumnarReadExt::read_typed_vec may read from uninitialized memory locatio…

Fix: after 0.0.19
Fix from $2,300 2021-12-27
Csv Sniffer CRITICAL 9.8
CVE-2021-45686

An issue was discovered in the csv-sniffer crate through 2021-01-05 for Rust. preamble_skipcount may read from uninitialized memory locations.

Mitigation only
Fix from $2,300 2021-12-27
Ash CRITICAL 9.8
CVE-2021-45688

An issue was discovered in the ash crate before 0.33.1 for Rust. util::read_spv may read from uninitialized memory locations.

Fix: 0.33.1+
Fix from $2,300 2021-12-27
Gfx Auxil CRITICAL 9.8
CVE-2021-45689

An issue was discovered in the gfx-auxil crate through 2021-01-07 for Rust. gfx_auxil::read_spirv may read from uninitialized memory locations.

Fix: after 0.10.0
Fix from $2,300 2021-12-27
Messagepack Rs CRITICAL 9.8
CVE-2021-45690

An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_binary may read from uninitialized memory locations.

Fix: 0.8.1+
Fix from $2,300 2021-12-27
Messagepack Rs CRITICAL 9.8
CVE-2021-45691

An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations.

Fix: 0.8.1+
Fix from $2,300 2021-12-27
Messagepack Rs CRITICAL 9.8
CVE-2021-45692

An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory loca…

Fix: 0.8.1+
Fix from $2,300 2021-12-27
Messagepack Rs CRITICAL 9.8
CVE-2021-45693

An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string_primitive may read from uninitialized memory loca…

Fix: 0.8.1+
Fix from $2,300 2021-12-27
Rdiff HIGH 7.5
CVE-2021-45694

An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locations.

Fix: after 0.1.2
Fix from $1,950 2021-12-27
Tectonic Xdv CRITICAL 9.8
CVE-2021-45703

An issue was discovered in the tectonic_xdv crate before 0.1.12 for Rust. XdvParser::<T>::process may read from uninitialized memory locations.

Fix: 0.1.12+
Fix from $2,300 2021-12-27
Bite HIGH 7.5
CVE-2020-36511

An issue was discovered in the bite crate through 2020-12-31 for Rust. read::BiteReadExpandedExt::read_framed_max may read from uninitialized memory …

Fix: after 0.0.5
Fix from $1,950 2021-12-27
Buffoon CRITICAL 9.8
CVE-2020-36512

An issue was discovered in the buffoon crate through 2020-12-31 for Rust. InputStream::read_exact may read from uninitialized memory locations.

Mitigation only
Fix from $2,300 2021-12-27
Acc Reader CRITICAL 9.8
CVE-2020-36513

An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. read_up_to may read from uninitialized memory locations.

Fix: after 2.0.0
Fix from $2,300 2021-12-27
Acc Reader CRITICAL 9.8
CVE-2020-36514

An issue was discovered in the acc_reader crate through 2020-12-27 for Rust. fill_buf may read from uninitialized memory locations.

Fix: after 2.0.0
Fix from $2,300 2021-12-27
Bronzedb Protocol CRITICAL 9.8
CVE-2021-45682

An issue was discovered in the bronzedb-protocol crate through 2021-01-03 for Rust. ReadKVExt may read from uninitialized memory locations.

Mitigation only
Fix from $2,300 2021-12-27