Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux CRITICAL 9.1
CVE-2017-7753

An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects …

Fix: 52.3.0 / 55.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-7754

An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefo…

Fix: 52.2.0 / 54.0+
Fix from $1,950 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5446

An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable…

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11
Debian Linux MEDIUM 6.5
CVE-2018-11439

The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based bu…

No fix yet
Fix from $1,600 2018-05-30
Debian Linux MEDIUM 5.5
CVE-2018-11503

The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer ove…

Mitigation only
Fix from $1,600 2018-05-26
Debian Linux MEDIUM 5.5
CVE-2018-11504

The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-re…

Mitigation only
Fix from $1,600 2018-05-26
Debian Linux MEDIUM 5.5
CVE-2018-11468

The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer o…

No fix yet
Fix from $1,600 2018-05-25
Debian Linux CRITICAL 9.1
CVE-2018-1000301EPSS 6%

curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl…

Fix: 7.2+
Fix from $2,300 2018-05-24
Debian Linux MEDIUM 6.5
CVE-2018-10999

An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer over-read.

No fix yet
Fix from $1,600 2018-05-12
Debian Linux HIGH 8.8
CVE-2018-10392

mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial …

No fix yet
Fix from $1,950 2018-04-26
Debian Linux HIGH 7.5
CVE-2018-10393

bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.

Mitigation only
Fix from $1,950 2018-04-26
Debian Linux HIGH 7.5
CVE-2018-6798

An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and…

Fix: after 5.26
Fix from $1,950 2018-04-17
Debian Linux MEDIUM 6.5
CVE-2018-10001

The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) …

Fix: after 3.4.2
Fix from $1,600 2018-04-11
Debian Linux MEDIUM 6.5
CVE-2018-3838

An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially cr…

No fix yet
Fix from $1,600 2018-04-10
Debian Linux MEDIUM 5.5
CVE-2018-3837

An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A s…

No fix yet
Fix from $1,600 2018-04-10
Debian Linux HIGH 7.5
CVE-2018-9988

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on inva…

Fix: 2.1.11 / 2.7.2+
Fix from $1,950 2018-04-10
Debian Linux HIGH 7.5
CVE-2018-9989

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid …

Fix: 2.1.11 / 2.7.2+
Fix from $1,950 2018-04-10
Debian Linux MEDIUM 6.5
CVE-2018-8976

In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a c…

Patch available
Fix from $1,600 2018-03-25
Debian Linux MEDIUM 5.5
CVE-2018-8754

The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values…

Fix: 20180317+
Fix from $1,600 2018-03-18
Debian Linux CRITICAL 9.1
CVE-2018-1000122EPSS 9%

A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of serv…

Fix: 7.2+
Fix from $2,300 2018-03-14
Debian Linux MEDIUM 5.5
CVE-2018-1000085

ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Lea…

Patch available
Fix from $1,600 2018-03-13
Debian Linux MEDIUM 6.5
CVE-2018-7875

There is a heap-based buffer over-read in the getString function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead t…

No fix yet
Fix from $1,600 2018-03-08
Debian Linux HIGH 8.8
CVE-2018-7871

There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT16 data. A crafted input will lead to…

No fix yet
Fix from $1,950 2018-03-08
Debian Linux MEDIUM 6.5
CVE-2018-7868

There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead to …

No fix yet
Fix from $1,600 2018-03-08
Debian Linux MEDIUM 5.5
CVE-2018-7730

An issue was discovered in Exempi through 2.4.4. A certain case of a 0xffffffff length is mishandled in XMPFiles/source/FormatSupport/PSIR_FileWriter…

Fix: after 2.4.4
Fix from $1,600 2018-03-06
Debian Linux HIGH 7.1
CVE-2017-14461EPSS 17%

A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive info…

Patch available
Fix from $1,950 2018-03-02
Debian Linux HIGH 8.8
CVE-2018-7550

The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU hos…

Patch available
Fix from $1,950 2018-03-01
Debian Linux MEDIUM 6.5
CVE-2018-7557

The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denial of service (Out of array re…

Fix: after 3.4.2
Fix from $1,600 2018-02-28
Debian Linux HIGH 8.8
CVE-2018-7435

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7436

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23