Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux CRITICAL 9.8
CVE-2022-24786

PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI…

Fix: after 2.12
Fix from $2,300 2022-04-06
Debian Linux HIGH 7.1
CVE-2021-4156

An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricki…

Patch available
Fix from $1,950 2022-03-23
Debian Linux HIGH 8.1
CVE-2021-42387

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit uns…

Fix: 21.10.2.15+
Fix from $1,950 2022-03-14
Debian Linux HIGH 8.1
CVE-2021-42388

Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit uns…

Fix: 21.10.2.15+
Fix from $1,950 2022-03-14
Debian Linux MEDIUM 5.5
CVE-2022-0924

Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile lib…

Patch available
Fix from $1,600 2022-03-11
Debian Linux CRITICAL 9.1
CVE-2021-33293

Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c.

Patch available
Fix from $2,300 2022-03-10
Debian Linux HIGH 8.8
CVE-2021-44142EPSS 74%

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperabilit…

Mitigation only
Fix from $1,950 2022-02-21
Debian Linux CRITICAL 9.1
CVE-2021-43302

Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause an out-of-bounds read when t…

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux MEDIUM 5.5
CVE-2022-0534

A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malici…

Patch available
Fix from $1,600 2022-02-09
Debian Linux MEDIUM 5.3
CVE-2021-46671

options.c in atftp before 0.7.5 reads past the end of an array, and consequently discloses server-side /etc/group data to a remote client.

Fix: 0.7.5+
Fix from $1,600 2022-02-04
Debian Linux CRITICAL 9.1
CVE-2022-23096

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient He…

Fix: after 1.40
Fix from $2,300 2022-01-28
Debian Linux CRITICAL 9.1
CVE-2022-23097

An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.

Fix: after 1.40
Fix from $2,300 2022-01-28
Debian Linux CRITICAL 9.1
CVE-2022-21722

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.11.1
Fix from $2,300 2022-01-27
Debian Linux CRITICAL 9.1
CVE-2022-21723

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: 16.24.1 / 18.10.1+
Fix from $2,300 2022-01-27
Debian Linux HIGH 7.8
CVE-2022-0368

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4217 / 12.6+
Fix from $1,950 2022-01-26
Debian Linux MEDIUM 5.5
CVE-2022-0319

Out-of-bounds Read in vim/vim prior to 8.2.

Fix: 8.2.4154 / 13.0+
Fix from $1,600 2022-01-21
Debian Linux HIGH 7.5
CVE-2022-20698

A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allo…

Fix: 0.103.5 / 0.104.2+
Fix from $1,950 2022-01-14
Debian Linux MEDIUM 5.5
CVE-2021-36411

An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ memory access in function derive_boundaryStrength…

No fix yet
Fix from $1,600 2022-01-10
Debian Linux MEDIUM 6.5
CVE-2021-35452

An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.

No fix yet
Fix from $1,600 2022-01-10
Debian Linux MEDIUM 5.5
CVE-2022-22844

LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of th…

No fix yet
Fix from $1,600 2022-01-10
Debian Linux CRITICAL 9.1
CVE-2021-43845

PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data fi…

Fix: after 2.11.1
Fix from $2,300 2021-12-27
Debian Linux HIGH 7.3
CVE-2021-43804

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.11.1
Fix from $1,950 2021-12-22
Debian Linux MEDIUM 5.5
CVE-2021-40985

A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.

Fix: 1.9.12+
Fix from $1,600 2021-11-03
Debian Linux MEDIUM 5.5
CVE-2021-40716

XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.…

Fix: after 2021.07
Fix from $1,600 2021-09-29
Debian Linux MEDIUM 5.5
CVE-2020-21535

fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux HIGH 7.8
CVE-2021-39255

A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39258

A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39252

A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39253

A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.5
CVE-2021-40516

WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in…

Fix: 3.2.1+
Fix from $1,950 2021-09-05