Vulnerability index

Browse CVEs

745 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
365 Apps HIGH 7.8
CVE-2020-16932

<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker…

Patch available
Fix from $1,950 2020-10-16
Android MEDIUM 6.5
CVE-2020-0411

In ~AACExtractor() of AACExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could lead to remote information disc…

Patch available
Fix from $1,600 2020-10-14
Md4c HIGH 7.5
CVE-2020-26148

md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion f…

Patch available
Fix from $1,950 2020-09-30
Tensorflow HIGH 7.1
CVE-2020-15193

In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized memory resulting in further …

Patch available
Fix from $1,950 2020-09-25
Android HIGH 7.5
CVE-2020-0300

In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional executi…

Mitigation only
Fix from $1,950 2020-09-18
Android MEDIUM 6.7
CVE-2020-0326

In NFC, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution pri…

Mitigation only
Fix from $1,600 2020-09-18
Android MEDIUM 6.5
CVE-2020-0361

In libDRCdec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no addition…

Mitigation only
Fix from $1,600 2020-09-17
Android MEDIUM 6.5
CVE-2020-0340

In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with…

Mitigation only
Fix from $1,600 2020-09-17
Android HIGH 8.8
CVE-2020-0321

In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional …

Mitigation only
Fix from $1,950 2020-09-17
Objective Open Cbor Run Time CRITICAL 9.8
CVE-2020-24753

A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execute code vi…

Fix: 2020-08-12+
Fix from $2,300 2020-09-17
Office MEDIUM 5.5
CVE-2020-16855

<p>An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which co…

Patch available
Fix from $1,600 2020-09-11
Apq8009 Firmware CRITICAL 9.8
CVE-2019-14052

u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing' in Snapdragon Auto, Snapdrag…

Mitigation only
Fix from $2,300 2020-09-08
Vm Virtualbox MEDIUM 6.0
CVE-2020-14703

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.44 / 6.0.24+
Fix from $1,600 2020-07-15
Vm Virtualbox MEDIUM 6.0
CVE-2020-14704

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.44 / 6.0.24+
Fix from $1,600 2020-07-15
365 Apps MEDIUM 5.5
CVE-2020-1342EPSS 6%

An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could…

Patch available
Fix from $1,600 2020-07-14
Python HIGH 7.8
CVE-2020-15523

In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used i…

Fix: 3.5.10 / 3.6.12+
Fix from $1,950 2020-07-04
Android MEDIUM 6.5
CVE-2020-0195

In ihevcd_iquant_itrans_recon_ctb of ihevcd_iquant_itrans_recon_ctb.c and related functions, there is a possible information disclosure due to uninit…

Patch available
Fix from $1,600 2020-06-11
Janus HIGH 7.5
CVE-2020-13899

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses information fr…

Fix: after 0.10.0
Fix from $1,950 2020-06-10
365 Apps MEDIUM 6.5
CVE-2020-1322EPSS 5%

An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized variable, aka 'Microsoft Proj…

Patch available
Fix from $1,600 2020-06-09
Windows 10 HIGH 7.5
CVE-2020-1206EPSS 9%

An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, ak…

Patch available
Fix from $1,950 2020-06-09
Debian Linux HIGH 8.2
CVE-2020-13113

An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-afte…

Fix: 0.6.22+
Fix from $1,950 2020-05-21
Android MEDIUM 5.5
CVE-2020-0101

In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information di…

Patch available
Fix from $1,600 2020-05-14
Ruby MEDIUM 5.3
CVE-2020-10933

An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buff…

Fix: after 2.6.5
Fix from $1,600 2020-05-04
Vm Virtualbox HIGH 7.5
CVE-2020-2575

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4…

Fix: 5.2.40 / 6.0.20+
Fix from $1,950 2020-04-29
FreeBSD MEDIUM 5.3
CVE-2020-7451

In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, and 11.3-RELEASE before 11.3-RELEASE-p7, a TC…

Patch available
Fix from $1,600 2020-04-28
Firefox HIGH 7.5
CVE-2020-6821

When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires t…

Fix: 68.7.0 / 75.0+
Fix from $1,950 2020-04-24
Coloros HIGH 7.5
CVE-2020-11828

In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is def…

Mitigation only
Fix from $1,950 2020-04-21
Android MEDIUM 6.8
CVE-2019-20785

An issue was discovered on LG mobile devices with Android OS 8.0 and 8.1 software for the DTAG carrier. RILD in the radio layer uses an uninitialized…

Mitigation only
Fix from $1,600 2020-04-17
Chrome MEDIUM 6.3
CVE-2020-6444

Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 81.0.4044.92+
Fix from $1,600 2020-04-13
HTTP Server MEDIUM 5.3
CVE-2020-1934EPSS 52%

In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.

Fix: after 2.4.41
Fix from $1,600 2020-04-01