Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux HIGH 7.5
CVE-2018-14461

The LDP parser in tcpdump before 4.9.3 has a buffer over-read in print-ldp.c:ldp_tlv_print().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14464

The LMP parser in tcpdump before 4.9.3 has a buffer over-read in print-lmp.c:lmp_print_data_link_subobjs().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14466

The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14467

The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).

Fix: 4.9.3 / 10.15.2+
Fix from $1,950 2019-10-03
Debian Linux HIGH 7.5
CVE-2018-14468

The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().

Fix: after 15.0.1
Fix from $1,950 2019-10-03
Debian Linux MEDIUM 6.5
CVE-2018-21016

audio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-re…

No fix yet
Fix from $1,600 2019-09-16
Debian Linux HIGH 8.8
CVE-2015-9381

FreeType before 2.6.1 has a heap-based buffer over-read in T1_Get_Private_Dict in type1/t1parse.c.

Fix: 2.6.1+
Fix from $1,950 2019-09-03
Debian Linux MEDIUM 6.5
CVE-2015-9382

FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face…

Fix: 2.6.1+
Fix from $1,600 2019-09-03
Debian Linux MEDIUM 6.5
CVE-2015-9383

FreeType before 2.6.2 has a heap-based buffer over-read in tt_cmap14_validate in sfnt/ttcmap.c.

Fix: 2.6.2+
Fix from $1,600 2019-09-03
Debian Linux HIGH 7.8
CVE-2019-14776

A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.

Patch available
Fix from $1,950 2019-08-29
Debian Linux HIGH 7.8
CVE-2019-14437

The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap…

Patch available
Fix from $1,950 2019-08-29
Debian Linux HIGH 7.8
CVE-2019-14438

A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a…

Patch available
Fix from $1,950 2019-08-29
Debian Linux MEDIUM 6.5
CVE-2019-15531

GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.

Fix: after 1.9
Fix from $1,600 2019-08-23
Debian Linux MEDIUM 5.5
CVE-2019-15145

DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image…

Patch available
Fix from $1,600 2019-08-18
Debian Linux MEDIUM 5.5
CVE-2019-15142

In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup …

Patch available
Fix from $1,600 2019-08-18
Debian Linux HIGH 7.1
CVE-2019-13222

An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service o…

Fix: after 2019-03-04
Fix from $1,950 2019-08-15
Debian Linux HIGH 7.5
CVE-2019-14513

Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation be…

Fix: 2.76+
Fix from $1,950 2019-08-01
Debian Linux MEDIUM 6.5
CVE-2019-14380

libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files.

Fix: 0.4.5+
Fix from $1,600 2019-07-30
Debian Linux MEDIUM 6.5
CVE-2019-14370

In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result in denial of service.

No fix yet
Fix from $1,600 2019-07-28
Debian Linux MEDIUM 6.5
CVE-2019-14369

Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-based buffer over-read) via a …

No fix yet
Fix from $1,600 2019-07-28
Debian Linux CRITICAL 9.8
CVE-2019-13962

lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not pr…

Fix: after 3.0.7
Fix from $2,300 2019-07-18
Debian Linux HIGH 8.1
CVE-2019-13115EPSS 12%

In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-b…

Fix: 1.9.0+
Fix from $1,950 2019-07-16
Debian Linux HIGH 8.1
CVE-2019-13616

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called f…

No fix yet
Fix from $1,950 2019-07-16
Debian Linux MEDIUM 5.9
CVE-2019-12529EPSS 8%

An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authenticati…

Fix: 2.7+
Fix from $1,600 2019-07-11
Debian Linux MEDIUM 6.5
CVE-2019-13504

There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.

Fix: after 0.27.2
Fix from $1,600 2019-07-11
Debian Linux HIGH 8.8
CVE-2019-13297

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a height of zero is mishandled.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 8.8
CVE-2019-13295

ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a width of zero is mishandled.

Patch available
Fix from $1,950 2019-07-05
Debian Linux MEDIUM 5.5
CVE-2019-2101

In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local infor…

No fix yet
Fix from $1,600 2019-06-07
Debian Linux CRITICAL 9.8
CVE-2019-11766

dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.

Fix: 6.11.7 / 7.2.2+
Fix from $2,300 2019-05-05
Debian Linux MEDIUM 5.3
CVE-2019-11579

dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED.

Fix: 7.2.1+
Fix from $1,600 2019-04-28