Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux HIGH 7.5
CVE-2026-1940

An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsiz…

Fix: 1.28.1+
Fix from $1,950 2026-03-23
Debian Linux MEDIUM 5.9
CVE-2025-64098

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.…

Fix: 2.6.11 / 3.3.1+
Fix from $1,600 2026-02-03
Debian Linux HIGH 7.5
CVE-2025-62603

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). ParticipantGenericMessage is …

Fix: 2.6.11 / 3.3.1+
Fix from $1,950 2026-02-03
Debian Linux HIGH 7.1
CVE-2024-53150 KEV

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current…

Fix: 5.4.287 / 5.10.231+
Fix from $1,950 2024-12-24
Debian Linux HIGH 7.8
CVE-2024-46956

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code …

Fix: 10.04.0+
Fix from $1,950 2024-11-10
Debian Linux MEDIUM 5.5
CVE-2024-46955

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color spa…

Fix: 10.04.0+
Fix from $1,600 2024-11-10
Debian Linux HIGH 8.1
CVE-2024-41311

In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an o…

Patch available
Fix from $1,950 2024-10-15
Debian Linux CRITICAL 9.1
CVE-2024-37371

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens wi…

Fix: 1.21.3+
Fix from $2,300 2024-06-28
Debian Linux HIGH 7.5
CVE-2023-31122

Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.

Fix: 2.4.58+
Fix from $1,950 2023-10-23
Debian Linux CRITICAL 9.1
CVE-2023-40188

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-…

Fix: 2.11.0+
Fix from $2,300 2023-08-31
Debian Linux CRITICAL 9.1
CVE-2023-40181

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Integer…

Fix: 2.11.0+
Fix from $2,300 2023-08-31
Debian Linux CRITICAL 9.1
CVE-2023-39353

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to a missing …

Fix: 2.11.0+
Fix from $2,300 2023-08-31
Debian Linux CRITICAL 9.1
CVE-2023-39356

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a missing offset valid…

Fix: 2.11.0+
Fix from $2,300 2023-08-31
Debian Linux HIGH 7.5
CVE-2023-39354

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-…

Fix: 2.11.0+
Fix from $1,950 2023-08-31
Debian Linux CRITICAL 9.1
CVE-2023-41360

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

Fix: after 9.0
Fix from $2,300 2023-08-29
Debian Linux MEDIUM 5.5
CVE-2022-48554

File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.

No fix yet
Fix from $1,600 2023-08-22
Debian Linux MEDIUM 5.9
CVE-2020-22217

Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.

Patch available
Fix from $1,600 2023-08-22
Debian Linux MEDIUM 6.5
CVE-2022-43681

An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that ends with the option leng…

Fix: after 8.4
Fix from $1,600 2023-05-03
Debian Linux MEDIUM 6.5
CVE-2022-40302

An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC …

Fix: after 8.4
Fix from $1,600 2023-05-03
Debian Linux MEDIUM 6.5
CVE-2022-40318

An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC …

Fix: after 8.4
Fix from $1,600 2023-05-03
Debian Linux CRITICAL 9.8
CVE-2022-23123

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to…

Fix: 3.1.13+
Fix from $2,300 2023-03-28
Debian Linux CRITICAL 9.8
CVE-2022-23124

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to…

Fix: 3.1.13+
Fix from $2,300 2023-03-28
Debian Linux CRITICAL 9.8
CVE-2022-4338

An integer underflow in Organization Specific TLV was found in various versions of OpenvSwitch.

Fix: 2.13.10 / 2.14.8+
Fix from $2,300 2023-01-10
Debian Linux CRITICAL 9.8
CVE-2022-4337

An out-of-bounds read in Organization Specific TLV was found in various versions of OpenvSwitch.

Fix: 2.13.10 / 2.14.8+
Fix from $2,300 2023-01-10
Debian Linux MEDIUM 5.9
CVE-2022-43592

An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially craft…

No fix yet
Fix from $1,600 2022-12-22
Debian Linux MEDIUM 5.9
CVE-2022-43596

An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A spe…

No fix yet
Fix from $1,600 2022-12-22
Debian Linux HIGH 8.1
CVE-2022-41981

A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0. A specially-crafted targa file can lead to…

No fix yet
Fix from $1,950 2022-12-22
Debian Linux HIGH 7.5
CVE-2022-41988

An information disclosure vulnerability exists in the OpenImageIO::decode_iptc_iim() functionality of OpenImageIO Project OpenImageIO v2.3.19.0. A sp…

No fix yet
Fix from $1,950 2022-12-22
Debian Linux CRITICAL 9.1
CVE-2022-41649

A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0. A specially-crafted T…

No fix yet
Fix from $2,300 2022-12-22
Debian Linux CRITICAL 9.8
CVE-2022-23537

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: 2.13.1+
Fix from $2,300 2022-12-20