Vulnerability index

Browse CVEs

745 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
Android MEDIUM 5.5
CVE-2018-9499

In readVector of iCrypto.cpp, there is a possible invalid read due to uninitialized data. This could lead to local information disclosure from the DR…

Patch available
Fix from $1,600 2018-10-02
Atlantis Word Processor HIGH 7.8
CVE-2018-3975

An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3.2.6 version. A specially cra…

No fix yet
Fix from $1,950 2018-10-01
Debian Linux HIGH 7.8
CVE-2018-15911

In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode ope…

Patch available
Fix from $1,950 2018-08-28
Godot HIGH 7.5
CVE-2018-1000224

Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, …

Fix: 2.1.5 / 3.0.6+
Fix from $1,950 2018-08-20
Excel Viewer MEDIUM 5.5
CVE-2018-8378EPSS 8%

An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could…

Patch available
Fix from $1,600 2018-08-15
Ubuntu Linux CRITICAL 9.8
CVE-2018-14551

The ReadMATImageV4 function in coders/mat.c in ImageMagick 7.0.8-7 uses an uninitialized variable, leading to memory corruption.

No fix yet
Fix from $2,300 2018-07-23
Ubuntu Linux HIGH 7.5
CVE-2018-5160

WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC en…

Fix: 60.0+
Fix from $1,950 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5095

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This result…

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Radare2 MEDIUM 5.5
CVE-2018-11383

The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted…

Patch available
Fix from $1,600 2018-05-22
7 Zip HIGH 7.8
CVE-2018-10115

Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers …

Fix: after 18.03
Fix from $1,950 2018-05-02
Fusion MEDIUM 5.5
CVE-2017-4905

VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 with…

Fix: 8.5.6 / 12.5.5+
Fix from $1,600 2017-06-07
Debian Linux HIGH 7.5
CVE-2017-9098

ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive infor…

Fix: 1.3.24 / 6.9.8-1+
Fix from $1,950 2017-05-19
Linux Kernel MEDIUM 5.5
CVE-2016-0821

The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consi…

Fix: 4.3+
Fix from $1,600 2016-03-12
Fedora CRITICAL 9.8
CVE-2015-8390

PCRE before 8.38 mishandles the [: and \\ substrings in character classes, which allows remote attackers to cause a denial of service (uninitialized …

Fix: 5.5.32 / 5.6.18+
Fix from $2,300 2015-12-02
Fedora HIGH 9.3
CVE-2015-5165EPSS 13%

The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read pro…

Patch available
Fix from $1,950 2015-08-12
SQLite HIGH 7.5
CVE-2015-3414

SQLite before 3.8.9 does not properly implement the dequoting of collation-sequence names, which allows context-dependent attackers to cause a denial…

Fix: 5.4.42 / 5.5.26+
Fix from $1,950 2015-04-24
Data Access Components CRITICAL 9.8
CVE-2012-1891EPSS 29%

Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote att…

Mitigation only
Fix from $2,300 2012-07-10
Linux Kernel HIGH 7.8
CVE-2009-3620

The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initializat…

Fix: 2.6.31.1+
Fix from $1,950 2009-10-22
Linux Kernel HIGH 7.8
CVE-2009-2692EPSS 15%

The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops str…

Fix: 2.4.37.5 / 2.6.30.5+
Fix from $1,950 2009-08-14
Ubuntu Linux HIGH 7.5
CVE-2009-0949EPSS 20%

The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote …

Fix: 1.3.10 / 10.4.11+
Fix from $1,950 2009-06-09
Opera Browser HIGH 8.8
CVE-2008-4197EPSS 6%

Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that conta…

Fix: 9.52+
Fix from $1,950 2008-09-27
Http Antivirus Proxy HIGH 7.5
CVE-2008-3688

sockethandler.cpp in HTTP Antivirus Proxy (HAVP) 0.88 allows remote attackers to cause a denial of service (hang) by connecting to a non-responsive s…

Patch available
Fix from $1,950 2008-08-14
Ubuntu Linux HIGH 8.8
CVE-2008-2934

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary cod…

No fix yet
Fix from $1,950 2008-07-18
Linux HIGH 7.5
CVE-2008-0063

The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, wh…

Fix: 10.4.11 / 10.5.2+
Fix from $1,950 2008-03-19
Excel CRITICAL 9.8
CVE-2008-0081EPSS 58%

Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to…

Patch available
Fix from $2,300 2008-01-16