Vulnerability index

Browse CVEs

745 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
Android HIGH 8.8
CVE-2019-2105

In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This could lead to remote code exe…

Mitigation only
Fix from $1,950 2019-07-08
Android MEDIUM 5.5
CVE-2019-2118

In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead to local information disclosur…

Mitigation only
Fix from $1,600 2019-07-08
Debian Linux HIGH 8.8
CVE-2019-13135

ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.

Fix: 6.9.10-50 / 7.0.8-50+
Fix from $1,950 2019-07-01
Debian Linux MEDIUM 5.3
CVE-2019-13117EPSS 6%

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This c…

Patch available
Fix from $1,600 2019-07-01
Chrome MEDIUM 6.5
CVE-2019-5818

Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from proces…

Fix: 74.0.3729.108+
Fix from $1,600 2019-06-27
Android MEDIUM 5.5
CVE-2019-2004

In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local informati…

Mitigation only
Fix from $1,600 2019-06-19
PHP MEDIUM 5.3
CVE-2019-11038

When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x be…

Fix: 7.1.30 / 7.2.19+
Fix from $1,600 2019-06-19
Mupdf CRITICAL 9.8
CVE-2019-7321

Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an atta…

Patch available
Fix from $2,300 2019-06-13
Ffmpeg CRITICAL 9.8
CVE-2019-12730

aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of u…

Fix: 3.2.14+
Fix from $2,300 2019-06-04
Qemu MEDIUM 5.5
CVE-2019-9824

tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure.

Patch available
Fix from $1,600 2019-06-03
Linux Kernel MEDIUM 5.5
CVE-2019-11833

fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local user…

Fix: after 5.1.2
Fix from $1,600 2019-05-15
Haproxy MEDIUM 5.9
CVE-2019-11323

HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to …

Fix: 1.9.7+
Fix from $1,600 2019-05-09
Firefox CRITICAL 9.8
CVE-2019-9805

A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory co…

Fix: 66.0+
Fix from $2,300 2019-04-26
Endpoint Protection MEDIUM 6.5
CVE-2018-18366

Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Ag…

Fix: 3.00.31.2817 / 22.16.3+
Fix from $1,600 2019-04-25
Ubuntu Linux MEDIUM 5.5
CVE-2019-11459

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle err…

Fix: after 3.32.0
Fix from $1,600 2019-04-22
PHP HIGH 7.5
CVE-2019-9639EPSS 8%

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in ex…

Fix: 7.1.27 / 7.2.16+
Fix from $1,950 2019-03-09
PHP CRITICAL 9.8
CVE-2019-9641EPSS 9%

An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in ex…

Fix: 7.1.27 / 7.2.16+
Fix from $2,300 2019-03-09
Libu2f Host HIGH 7.5
CVE-2019-9578

In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.

Fix: 1.1.8+
Fix from $1,950 2019-03-05
Android MEDIUM 5.5
CVE-2018-12011

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket address lead…

Patch available
Fix from $1,600 2019-02-11
Wibukey MEDIUM 5.5
CVE-2018-3989

An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (…

No fix yet
Fix from $1,600 2019-02-05
Libvips MEDIUM 5.3
CVE-2019-6976

libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c …

Fix: 8.7.4+
Fix from $1,600 2019-01-26
Junos CRITICAL 9.8
CVE-2019-0006EPSS 5%

A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on…

Mitigation only
Fix from $2,300 2019-01-15
Yara MEDIUM 5.5
CVE-2018-19974

In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow att…

No fix yet
Fix from $1,600 2018-12-17
Excel MEDIUM 5.5
CVE-2018-8627EPSS 8%

An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could …

Patch available
Fix from $1,600 2018-12-12
Dokany MEDIUM 5.5
CVE-2018-20029

The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) becau…

Fix: 6.4.6+
Fix from $1,600 2018-12-10
Android HIGH 7.8
CVE-2018-9557

In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninitialized data. This could lead to local escalation…

Mitigation only
Fix from $1,950 2018-12-06
Workstation HIGH 8.8
CVE-2018-6981

VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware W…

Fix: 10.1.4 / 14.1.4+
Fix from $1,950 2018-12-04
Workstation MEDIUM 6.5
CVE-2018-6982

VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3…

Fix: 10.1.4 / 14.1.4+
Fix from $1,600 2018-12-04
Wireshark MEDIUM 5.5
CVE-2018-19626

In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' t…

Fix: after 2.6.4
Fix from $1,600 2018-11-29
Hitmanpro.alert MEDIUM 5.5
CVE-2018-3970

An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially cr…

No fix yet
Fix from $1,600 2018-10-25