Vulnerability index

Browse CVEs

745 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
Binjs Io CRITICAL 9.8
CVE-2021-45683

An issue was discovered in the binjs_io crate through 2021-01-03 for Rust. The Read method may read from uninitialized memory locations.

No fix yet
Fix from $2,300 2021-12-27
Flumedb CRITICAL 9.8
CVE-2021-45684

An issue was discovered in the flumedb crate through 2021-01-07 for Rust. read_entry may read from uninitialized memory locations.

Fix: after 0.1.5
Fix from $2,300 2021-12-27
Smallvec HIGH 7.5
CVE-2018-25023

An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.

Fix: 0.6.13+
Fix from $1,950 2021-12-27
Davinci Resolve CRITICAL 9.8
CVE-2021-40418EPSS 18%

When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containin…

No fix yet
Fix from $2,300 2021-12-22
Jt2go MEDIUM 5.5
CVE-2021-44003

A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll is …

Fix: 13.2.0.5+
Fix from $1,600 2021-12-14
Zydis HIGH 8.1
CVE-2021-41253

Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions provided in `zycore` in order to …

Fix: after 3.2.0
Fix from $1,950 2021-11-08
Tensorflow HIGH 7.8
CVE-2021-41225

TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's Grappler optimizer has a use of unitialized variable. I…

Fix: 2.4.4 / 2.5.2+
Fix from $1,950 2021-11-05
Fedora HIGH 7.8
CVE-2021-3928

vim is vulnerable to Use of Uninitialized Variable

Fix: 8.2.3582+
Fix from $1,950 2021-11-05
Parallels Desktop MEDIUM 6.5
CVE-2021-34855

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.1.3 (49160). An attacke…

Patch available
Fix from $1,600 2021-10-25
Android MEDIUM 6.7
CVE-2021-0634

In display driver, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege with System exec…

Mitigation only
Fix from $1,600 2021-10-25
Android MEDIUM 5.5
CVE-2021-0938

In memzero_explicit of compiler-clang.h, there is a possible bypass of defense in depth due to uninitialized data. This could lead to local informati…

Mitigation only
Fix from $1,600 2021-10-25
Bulletin Board System HIGH 7.5
CVE-2021-36512

An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information …

Patch available
Fix from $1,950 2021-10-19
Ios Xe CRITICAL 9.1
CVE-2021-1619

A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote a…

Mitigation only
Fix from $2,300 2021-09-23
FreeBSD HIGH 7.8
CVE-2021-29631

In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE before p4, 12.2-RELEASE befo…

Mitigation only
Fix from $1,950 2021-08-30
Instruction Set Manual CRITICAL 9.8
CVE-2021-1104

The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) register that may lead to a vulner…

No fix yet
Fix from $2,300 2021-08-13
Tensorflow HIGH 7.1
CVE-2021-37682

TensorFlow is an end-to-end open source platform for machine learning. In affected versions all TFLite operations that use quantization can be made t…

Fix: 2.3.4 / 2.4.3+
Fix from $1,950 2021-08-12
Libp2p Deflate CRITICAL 9.8
CVE-2020-36443

An issue was discovered in the libp2p-deflate crate before 0.27.1 for Rust. An uninitialized buffer is passed to AsyncRead::poll_read(), which is a u…

Fix: 0.27.1+
Fix from $2,300 2021-08-08
Array Tools CRITICAL 9.8
CVE-2020-36452

An issue was discovered in the array-tools crate before 0.3.2 for Rust. FixedCapacityDequeLike::clone() has a drop of uninitialized memory.

Fix: 0.3.2+
Fix from $2,300 2021-08-08
Alg Ds CRITICAL 9.8
CVE-2020-36432

An issue was discovered in the alg_ds crate through 2020-08-25 for Rust. There is a drop of uninitialized memory in Matrix::new().

Fix: after 2020-08-25
Fix from $2,300 2021-08-08
Curl MEDIUM 5.3
CVE-2021-22925

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pair…

Fix: 7.78.0+
Fix from $1,600 2021-08-05
Chrome HIGH 8.8
CVE-2021-30578

Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform out of bounds memory access via a crafted HTM…

Fix: 92.0.4515.107+
Fix from $1,950 2021-08-03
Android HIGH 7.8
CVE-2021-0526

In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with…

Mitigation only
Fix from $1,950 2021-06-21
Android HIGH 7.8
CVE-2021-0530

In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with…

Mitigation only
Fix from $1,950 2021-06-21
Android HIGH 7.8
CVE-2021-0495

In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with…

Mitigation only
Fix from $1,950 2021-06-11
Android HIGH 8.8
CVE-2021-0473

In rw_t3t_process_error of rw_t3t.cc, there is a possible double free due to uninitialized data. This could lead to remote code execution over NFC wi…

Patch available
Fix from $1,950 2021-06-11
Apq8017 Firmware HIGH 8.4
CVE-2020-11260

An improper free of uninitialized memory can occur in DIAG services in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

Mitigation only
Fix from $1,950 2021-06-09
Debian Linux MEDIUM 6.5
CVE-2021-3545

An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. T…

Fix: after 6.0.0
Fix from $1,600 2021-06-02
Enterprise Linux CRITICAL 9.8
CVE-2018-25014

A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Tensorflow MEDIUM 5.5
CVE-2021-29580

TensorFlow is an end-to-end open source platform for machine learning. The implementation of `tf.raw_ops.FractionalMaxPoolGrad` triggers an undefined…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14
Tensorflow MEDIUM 5.5
CVE-2021-29581

TensorFlow is an end-to-end open source platform for machine learning. Due to lack of validation in `tf.raw_ops.CTCBeamSearchDecoder`, an attacker ca…

Fix: 2.1.4 / 2.2.3+
Fix from $1,600 2021-05-14