Vulnerability index

Browse CVEs

745 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
HIGH 8.8 CVE-2019-2105 In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This could lead to remote code exe… Android Mitigation only Fix from $1,9502019-07-08 MEDIUM 5.5 CVE-2019-2118 In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead to local information disclosur… Android Mitigation only Fix from $1,6002019-07-08 HIGH 8.8 CVE-2019-13135 ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c. Debian Linux 6.9.10-50 / 7.0.8-50+ Fix from $1,9502019-07-01 MEDIUM 5.3 CVE-2019-13117EPSS 6% In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This c… Debian Linux Patch available Fix from $1,6002019-07-01 MEDIUM 6.5 CVE-2019-5818 Uninitialized data in media in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from proces… Chrome 74.0.3729.108+ Fix from $1,6002019-06-27 MEDIUM 5.5 CVE-2019-2004 In publishKeyEvent, publishMotionEvent and sendUnchainedFinishedSignal of InputTransport.cpp, there are uninitialized data leading to local informati… Android Mitigation only Fix from $1,6002019-06-19 MEDIUM 5.3 CVE-2019-11038 When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x be… PHP 7.1.30 / 7.2.19+ Fix from $1,6002019-06-19 CRITICAL 9.8 CVE-2019-7321 Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an atta… Mupdf Patch available Fix from $2,3002019-06-13 CRITICAL 9.8 CVE-2019-12730 aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and consequently allows use of u… Ffmpeg 3.2.14+ Fix from $2,3002019-06-04 MEDIUM 5.5 CVE-2019-9824 tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leading to Information disclosure. Qemu Patch available Fix from $1,6002019-06-03 MEDIUM 5.5 CVE-2019-11833 fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local user… Linux Kernel after 5.1.2 Fix from $1,6002019-05-15 MEDIUM 5.9 CVE-2019-11323 HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, HMAC keys. This is related to … Haproxy 1.9.7+ Fix from $1,6002019-05-09 CRITICAL 9.8 CVE-2019-9805 A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory co… Firefox 66.0+ Fix from $2,3002019-04-26 MEDIUM 6.5 CVE-2018-18366 Symantec Norton Security prior to 22.16.3, SEP (Windows client) prior to and including 12.1 RU6 MP9, and prior to 14.2 RU1, SEP SBE prior to Cloud Ag… Endpoint Protection 3.00.31.2817 / 22.16.3+ Fix from $1,6002019-04-25 MEDIUM 5.5 CVE-2019-11459 The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle err… Ubuntu Linux after 3.32.0 Fix from $1,6002019-04-22 HIGH 7.5 CVE-2019-9639EPSS 8% An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in ex… PHP 7.1.27 / 7.2.16+ Fix from $1,9502019-03-09 CRITICAL 9.8 CVE-2019-9641EPSS 9% An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in ex… PHP 7.1.27 / 7.2.16+ Fix from $2,3002019-03-09 HIGH 7.5 CVE-2019-9578 In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device. Libu2f Host 1.1.8+ Fix from $1,9502019-03-05 MEDIUM 5.5 CVE-2018-12011 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Uninitialized data for socket address lead… Android Patch available Fix from $1,6002019-02-11 MEDIUM 5.5 CVE-2018-3989 An exploitable kernel memory disclosure vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (… Wibukey No fix yet Fix from $1,6002019-02-05 MEDIUM 5.3 CVE-2019-6976 libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image data because iofuncs/memory.c … Libvips 8.7.4+ Fix from $1,6002019-01-26 CRITICAL 9.8 CVE-2019-0006EPSS 5% A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on… Junos Mitigation only Fix from $2,3002019-01-15 MEDIUM 5.5 CVE-2018-19974 In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow att… Yara No fix yet Fix from $1,6002018-12-17 MEDIUM 5.5 CVE-2018-8627EPSS 8% An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could … Excel Patch available Fix from $1,6002018-12-12 MEDIUM 5.5 CVE-2018-20029 The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) becau… Dokany 6.4.6+ Fix from $1,6002018-12-10 HIGH 7.8 CVE-2018-9557 In really_install_package of install.cpp, there is a possible free of arbitrary memory due to uninitialized data. This could lead to local escalation… Android Mitigation only Fix from $1,9502018-12-06 HIGH 8.8 CVE-2018-6981 VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG, VMware ESXi 6.0 without ESXi600-201811401-BG, VMware W… Workstation 10.1.4 / 14.1.4+ Fix from $1,9502018-12-04 MEDIUM 6.5 CVE-2018-6982 VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG contain uninitialized stack memory usage in the vmxnet3… Workstation 10.1.4 / 14.1.4+ Fix from $1,6002018-12-04 MEDIUM 5.5 CVE-2018-19626 In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' t… Wireshark after 2.6.4 Fix from $1,6002018-11-29 MEDIUM 5.5 CVE-2018-3970 An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially cr… Hitmanpro.alert No fix yet Fix from $1,6002018-10-25