Vulnerability index

Browse CVEs

745 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
Parallels Desktop MEDIUM 6.5
CVE-2021-31417

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker …

Mitigation only
Fix from $1,600 2021-04-29
Parallels Desktop MEDIUM 6.5
CVE-2021-31418

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker …

Mitigation only
Fix from $1,600 2021-04-29
Parallels Desktop MEDIUM 6.5
CVE-2021-31419

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4-47270. An attacker …

Mitigation only
Fix from $1,600 2021-04-29
Parallels Desktop MEDIUM 6.0
CVE-2021-31423

This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.5-47309. An attacker …

Mitigation only
Fix from $1,600 2021-04-29
Md4c MEDIUM 5.5
CVE-2021-30027

md_analyze_line in md4c.c in md4c 0.4.7 allows attackers to trigger use of uninitialized memory, and cause a denial of service via a malformed Markdo…

Patch available
Fix from $1,600 2021-04-29
Chrome MEDIUM 5.5
CVE-2021-21218

Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 90.0.4430.72+
Fix from $1,600 2021-04-26
Uu Od HIGH 7.3
CVE-2021-29934

An issue was discovered in PartialReader in the uu_od crate before 0.0.4 for Rust. Attackers can read the contents of uninitialized memory locations …

Fix: 0.0.4+
Fix from $1,950 2021-04-01
Adtensor CRITICAL 9.8
CVE-2021-29936

An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via the FromIterator implementatio…

Fix: after 2021-01-11
Fix from $2,300 2021-04-01
Telemetry CRITICAL 9.8
CVE-2021-29937

An issue was discovered in the telemetry crate through 2021-02-17 for Rust. There is a drop of uninitialized memory if a value.clone() call panics wi…

Fix: after 2021-02-17
Fix from $2,300 2021-04-01
Android MEDIUM 5.5
CVE-2021-0463

In convertToHidl of convert.cpp, there is a possible out of bounds read due to uninitialized data from ReturnFrameworkMessage. This could lead to loc…

Mitigation only
Fix from $1,600 2021-03-10
Chrome HIGH 8.8
CVE-2021-21190

Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 89.0.4389.72+
Fix from $1,950 2021-03-09
Byte Struct CRITICAL 9.8
CVE-2021-28033

An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There can be a drop of uninitialized memory if a certain deserialization meth…

Fix: 0.6.1+
Fix from $2,300 2021-03-05
Stack Dst CRITICAL 9.8
CVE-2021-28035

An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a drop of uninitialized memory can occur up…

Fix: 0.6.1+
Fix from $2,300 2021-03-05
Toodee HIGH 7.5
CVE-2021-28029

An issue was discovered in the toodee crate before 0.3.0 for Rust. The row-insertion feature allows attackers to read the contents of uninitialized m…

Fix: 0.3.0+
Fix from $1,950 2021-03-05
Truetype HIGH 7.5
CVE-2021-28030

An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers can read the contents of uninitialized memory locations via a user-pr…

Fix: 0.30.1+
Fix from $1,950 2021-03-05
Calamine CRITICAL 9.8
CVE-2021-26951

An issue was discovered in the calamine crate before 0.17.0 for Rust. It allows attackers to overwrite heap-memory locations because Vec::set_len is …

Fix: 0.17.0+
Fix from $2,300 2021-02-09
Ms3d HIGH 7.5
CVE-2021-26952

An issue was discovered in the ms3d crate before 0.1.3 for Rust. It might allow attackers to obtain sensitive information from uninitialized memory l…

Fix: 0.1.3+
Fix from $1,950 2021-02-09
Postscript HIGH 7.5
CVE-2021-26953

An issue was discovered in the postscript crate before 0.14.0 for Rust. It might allow attackers to obtain sensitive information from uninitialized m…

Fix: 0.14.0+
Fix from $1,950 2021-02-09
Cdr CRITICAL 9.8
CVE-2021-26305

An issue was discovered in Deserializer::read_vec in the cdr crate before 0.2.4 for Rust. A user-provided Read implementation can gain access to the …

Fix: 0.2.4+
Fix from $2,300 2021-01-29
Bra CRITICAL 9.1
CVE-2021-25905

An issue was discovered in the bra crate before 0.1.1 for Rust. It lacks soundness because it can read uninitialized memory.

Fix: 0.1.1+
Fix from $2,300 2021-01-26
Autorand HIGH 7.8
CVE-2020-36210

An issue was discovered in the autorand crate before 0.2.3 for Rust. Because of impl Random on arrays, uninitialized memory can be dropped when a pan…

Fix: 0.2.3+
Fix from $1,950 2021-01-26
Chrome MEDIUM 6.5
CVE-2020-16042

Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process mem…

Fix: 87.0.4280.88+
Fix from $1,600 2021-01-08
Fedora MEDIUM 6.1
CVE-2020-35494

There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage…

Fix: 2.34+
Fix from $1,600 2021-01-04
Arr CRITICAL 9.8
CVE-2020-35888

An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitialized memory is dropped by Array::new_from_template.

Fix: after 2020-08-25
Fix from $2,300 2020-12-31
Simple Slab HIGH 7.5
CVE-2020-35893

An issue was discovered in the simple-slab crate before 0.3.3 for Rust. remove() has an off-by-one error, causing memory leakage and a drop of uninit…

Fix: 0.3.3+
Fix from $1,950 2020-12-31
Ozone CRITICAL 9.8
CVE-2020-35878

An issue was discovered in the ozone crate through 2020-07-04 for Rust. Memory safety is violated because of the dropping of uninitialized memory.

Fix: after 0.1.0
Fix from $2,300 2020-12-31
Tensorflow MEDIUM 5.3
CVE-2020-26266

In affected versions of TensorFlow under certain cases a saved model can trigger use of uninitialized values during code execution. This is caused by…

Fix: 1.15.5 / 2.0.4+
Fix from $1,600 2020-12-10
Azure Sphere MEDIUM 6.2
CVE-2020-16985

Azure Sphere Information Disclosure Vulnerability

Fix: 20.09+
Fix from $1,600 2020-11-11
Chrome MEDIUM 5.5
CVE-2020-15989

Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 86.0.4240.75+
Fix from $1,600 2020-11-03
365 Apps HIGH 7.8
CVE-2020-16931

<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker…

Patch available
Fix from $1,950 2020-10-16