Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux MEDIUM 5.4
CVE-2020-11087

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_AuthenticateMessage. This has been fixed in 2.1.0.

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 5.4
CVE-2020-11088

In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_NegotiateMessage. This has been fixed in 2.1.0.

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 6.5
CVE-2020-11019

In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 6.5
CVE-2020-11018

In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed. Malicious clients could trigger out of bound r…

Fix: after 2.0.0
Fix from $1,600 2020-05-29
Debian Linux CRITICAL 9.1
CVE-2020-13112

An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crash…

Fix: 0.6.22+
Fix from $2,300 2020-05-21
Apt MEDIUM 5.5
CVE-2020-3810

Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafte…

Fix: 2.1.2+
Fix from $1,600 2020-05-15
Debian Linux MEDIUM 5.0
CVE-2020-0093

In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local informati…

Fix: 0.6.22+
Fix from $1,600 2020-05-14
Debian Linux MEDIUM 5.9
CVE-2020-11042

In FreeRDP greater than 1.1 and before 2.0.0, there is an out-of-bounds read in update_read_icon_info. It allows reading a attacker-defined amount of…

Fix: 2.0.0+
Fix from $1,600 2020-05-07
Debian Linux HIGH 7.5
CVE-2020-6077

An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages…

No fix yet
Fix from $1,950 2020-03-24
Debian Linux HIGH 7.5
CVE-2020-0034

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information …

Mitigation only
Fix from $1,950 2020-03-10
Debian Linux MEDIUM 6.5
CVE-2019-20503

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

Fix: 0.9.4.0+
Fix from $1,600 2020-03-06
Debian Linux HIGH 7.5
CVE-2019-20387

repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of …

Fix: 0.7.6+
Fix from $1,950 2020-01-21
Debian Linux CRITICAL 9.1
CVE-2019-20367

nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).

Fix: 0.10.0+
Fix from $2,300 2020-01-08
Debian Linux CRITICAL 9.1
CVE-2019-19949

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_pr…

Fix: 6.9.10-43 / 7.0.8-43+
Fix from $2,300 2019-12-24
Debian Linux CRITICAL 9.1
CVE-2019-19953

In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.

Patch available
Fix from $2,300 2019-12-24
Debian Linux HIGH 7.5
CVE-2012-4428EPSS 10%

openslp: SLPIntersectStringList()' Function has a DoS vulnerability

Mitigation only
Fix from $1,950 2019-12-02
Debian Linux MEDIUM 5.5
CVE-2019-19479

An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsin…

Fix: after 0.19.0
Fix from $1,600 2019-12-01
Debian Linux MEDIUM 5.5
CVE-2019-19221

In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. Fo…

Patch available
Fix from $1,600 2019-11-21
Debian Linux HIGH 7.5
CVE-2019-19204EPSS 7%

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in re…

Fix: 6.9.4+
Fix from $1,950 2019-11-21
Debian Linux CRITICAL 9.8
CVE-2019-19012EPSS 11%

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offse…

Fix: after 6.9.3
Fix from $2,300 2019-11-17
Debian Linux HIGH 8.2
CVE-2019-17533

Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninit…

Patch available
Fix from $1,950 2019-10-13
Debian Linux CRITICAL 9.8
CVE-2019-17455

Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations,…

Fix: after 1.5
Fix from $2,300 2019-10-10
Debian Linux CRITICAL 9.1
CVE-2019-17362

In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 seque…

Fix: after 1.18.2
Fix from $2,300 2019-10-09
Debian Linux HIGH 7.5
CVE-2018-14470

The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14880EPSS 5%

The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().

Fix: after 15.0.1
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14881

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16227EPSS 7%

The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16228

The HNCP parser in tcpdump before 4.9.3 has a buffer over-read in print-hncp.c:print_prefix().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16230

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-16451

The SMB parser in tcpdump before 4.9.3 has buffer over-reads in print-smb.c:print_trans() for \MAILSLOT\BROWSE and \PIPE\LANMAN.

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03