Vulnerability index

Browse CVEs

745 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
HIGH 7.8 CVE-2020-16932 <p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker… 365 Apps Patch available Fix from $1,9502020-10-16 MEDIUM 6.5 CVE-2020-0411 In ~AACExtractor() of AACExtractor.cpp, there is a possible out of bounds write due to uninitialized data. This could lead to remote information disc… Android Patch available Fix from $1,6002020-10-14 HIGH 7.5 CVE-2020-26148 md_push_block_bytes in md4c.c in md4c 0.4.5 allows attackers to trigger use of uninitialized memory, and cause a denial of service (e.g., assertion f… Md4c Patch available Fix from $1,9502020-09-30 HIGH 7.1 CVE-2020-15193 In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized memory resulting in further … Tensorflow Patch available Fix from $1,9502020-09-25 HIGH 7.5 CVE-2020-0300 In NFC, there is a possible out of bounds read due to uninitialized data. This could lead to remote information disclosure with no additional executi… Android Mitigation only Fix from $1,9502020-09-18 MEDIUM 6.7 CVE-2020-0326 In NFC, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution pri… Android Mitigation only Fix from $1,6002020-09-18 MEDIUM 6.5 CVE-2020-0361 In libDRCdec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no addition… Android Mitigation only Fix from $1,6002020-09-17 MEDIUM 6.5 CVE-2020-0340 In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with… Android Mitigation only Fix from $1,6002020-09-17 HIGH 8.8 CVE-2020-0321 In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional … Android Mitigation only Fix from $1,9502020-09-17 CRITICAL 9.8 CVE-2020-24753 A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execute code vi… Objective Open Cbor Run Time 2020-08-12+ Fix from $2,3002020-09-17 MEDIUM 5.5 CVE-2020-16855 <p>An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which co… Office Patch available Fix from $1,6002020-09-11 CRITICAL 9.8 CVE-2019-14052 u'Accessing an uninitialized data structure could result in partially copying of contents and thus incorrect processing' in Snapdragon Auto, Snapdrag… Apq8009 Firmware Mitigation only Fix from $2,3002020-09-08 MEDIUM 6.0 CVE-2020-14703 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4… Vm Virtualbox 5.2.44 / 6.0.24+ Fix from $1,6002020-07-15 MEDIUM 6.0 CVE-2020-14704 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4… Vm Virtualbox 5.2.44 / 6.0.24+ Fix from $1,6002020-07-15 MEDIUM 5.5 CVE-2020-1342EPSS 6% An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could… 365 Apps Patch available Fix from $1,6002020-07-14 HIGH 7.8 CVE-2020-15523 In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used i… Python 3.5.10 / 3.6.12+ Fix from $1,9502020-07-04 MEDIUM 6.5 CVE-2020-0195 In ihevcd_iquant_itrans_recon_ctb of ihevcd_iquant_itrans_recon_ctb.c and related functions, there is a possible information disclosure due to uninit… Android Patch available Fix from $1,6002020-06-11 HIGH 7.5 CVE-2020-13899 An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_process_incoming_request in janus.c discloses information fr… Janus after 0.10.0 Fix from $1,9502020-06-10 MEDIUM 6.5 CVE-2020-1322EPSS 5% An information disclosure vulnerability exists when Microsoft Project reads out of bound memory due to an uninitialized variable, aka 'Microsoft Proj… 365 Apps Patch available Fix from $1,6002020-06-09 HIGH 7.5 CVE-2020-1206EPSS 9% An information disclosure vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, ak… Windows 10 Patch available Fix from $1,9502020-06-09 HIGH 8.2 CVE-2020-13113 An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-afte… Debian Linux 0.6.22+ Fix from $1,9502020-05-21 MEDIUM 5.5 CVE-2020-0101 In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information di… Android Patch available Fix from $1,6002020-05-14 MEDIUM 5.3 CVE-2020-10933 An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buff… Ruby after 2.6.5 Fix from $1,6002020-05-04 HIGH 7.5 CVE-2020-2575 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.4… Vm Virtualbox 5.2.40 / 6.0.20+ Fix from $1,9502020-04-29 MEDIUM 5.3 CVE-2020-7451 In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, and 11.3-RELEASE before 11.3-RELEASE-p7, a TC… FreeBSD Patch available Fix from $1,6002020-04-28 HIGH 7.5 CVE-2020-6821 When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires t… Firefox 68.7.0 / 75.0+ Fix from $1,9502020-04-24 HIGH 7.5 CVE-2020-11828 In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is def… Coloros Mitigation only Fix from $1,9502020-04-21 MEDIUM 6.8 CVE-2019-20785 An issue was discovered on LG mobile devices with Android OS 8.0 and 8.1 software for the DTAG carrier. RILD in the radio layer uses an uninitialized… Android Mitigation only Fix from $1,6002020-04-17 MEDIUM 6.3 CVE-2020-6444 Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM… Chrome 81.0.4044.92+ Fix from $1,6002020-04-13 MEDIUM 5.3 CVE-2020-1934EPSS 52% In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. HTTP Server after 2.4.41 Fix from $1,6002020-04-01