Vulnerability index

Browse CVEs

52 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Debian Linux HIGH 8.8
CVE-2021-43304

Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the L…

Fix: 21.10.2.15+
Fix from $1,950 2022-03-14
Debian Linux HIGH 8.8
CVE-2021-43305

Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the L…

Fix: 21.10.2.15+
Fix from $1,950 2022-03-14
Debian Linux HIGH 7.8
CVE-2022-0392

Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.

Fix: 8.2.4218 / 12.6+
Fix from $1,950 2022-01-28
Debian Linux HIGH 7.8
CVE-2022-0361

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4215 / 12.6+
Fix from $1,950 2022-01-26
Debian Linux HIGH 7.8
CVE-2022-0359

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4214 / 12.6+
Fix from $1,950 2022-01-26
Debian Linux CRITICAL 9.8
CVE-2022-0318

Heap-based Buffer Overflow in vim/vim prior to 8.2.

Fix: 8.2.4151 / 13.0+
Fix from $2,300 2022-01-21
Debian Linux HIGH 7.8
CVE-2022-0261

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4120 / 13.0+
Fix from $1,950 2022-01-18
Debian Linux MEDIUM 6.6
CVE-2022-0213

vim is vulnerable to Heap-based Buffer Overflow

Fix: 8.2+
Fix from $1,600 2022-01-14
Debian Linux HIGH 7.8
CVE-2021-36051EPSS 6%

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the …

Fix: after 2020.1
Fix from $1,950 2021-10-04
Debian Linux HIGH 7.8
CVE-2021-36050EPSS 5%

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the …

Fix: after 2020.1
Fix from $1,950 2021-09-01
Debian Linux MEDIUM 5.5
CVE-2021-36056

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the …

Fix: after 2020.1
Fix from $1,600 2021-09-01
Debian Linux HIGH 8.8
CVE-2021-31439

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology DiskStation Manager. Authenticat…

Fix: 3.1.13 / 6.2.3-25426-3+
Fix from $1,950 2021-05-21
Debian Linux HIGH 7.8
CVE-2020-27814

A heap-buffer overflow was found in the way openjpeg2 handled certain PNG format files. An attacker could use this flaw to cause an application crash…

Fix: 2.4.0+
Fix from $1,950 2021-01-26
Debian Linux MEDIUM 5.5
CVE-2020-25674

WriteOnePNGImage() from coders/png.c (the PNG coder) has a for loop with an improper exit condition that can allow an out-of-bounds READ via heap-buf…

Fix: 6.9.10-68 / 7.0.8-68+
Fix from $1,600 2020-12-08
Debian Linux MEDIUM 5.5
CVE-2020-25665

The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() because it needs to be offset by 2…

Fix: 6.9.10-68 / 7.0.8-68+
Fix from $1,600 2020-12-08
Debian Linux HIGH 7.4
CVE-2020-11061

In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's mem…

Fix: after 19.2.7
Fix from $1,950 2020-07-10
Debian Linux CRITICAL 9.8
CVE-2018-8793EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corrupti…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8797EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8800EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corrupti…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux HIGH 7.8
CVE-2016-8654

A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before…

Fix: 2.0.0+
Fix from $1,950 2018-08-01
Debian Linux HIGH 8.8
CVE-2016-9577

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to th…

Fix: 0.13.90+
Fix from $1,950 2018-07-27
Debian Linux HIGH 8.8
CVE-2017-13090EPSS 37%

The retr.c:fd_read_body() function is called when processing OK responses. When the response is sent chunked in wget before 1.19.2, the chunk parser …

Fix: after 1.19.1
Fix from $1,950 2017-10-27