Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux HIGH 8.1
CVE-2019-11455

A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of a…

Fix: 5.25.3+
Fix from $1,950 2019-04-22
Debian Linux CRITICAL 9.1
CVE-2019-11006

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attac…

Fix: after 1.3.31
Fix from $2,300 2019-04-08
Debian Linux HIGH 8.1
CVE-2019-11007

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attacke…

Fix: after 1.3.31
Fix from $1,950 2019-04-08
Debian Linux HIGH 8.1
CVE-2019-11009

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attacke…

Fix: after 1.3.31
Fix from $1,950 2019-04-08
Debian Linux MEDIUM 5.5
CVE-2019-1787

A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could all…

Fix: after 0.101.1
Fix from $1,600 2019-04-08
Debian Linux HIGH 7.5
CVE-2018-10242

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the alloca…

Mitigation only
Fix from $1,950 2019-04-04
Debian Linux HIGH 8.1
CVE-2019-10650

In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to caus…

Patch available
Fix from $1,950 2019-03-30
Debian Linux CRITICAL 9.1
CVE-2019-3860EPSS 5%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compr…

Fix: after 1.8.0
Fix from $2,300 2019-03-25
Debian Linux CRITICAL 9.1
CVE-2019-3861EPSS 5%

An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length a…

Fix: after 1.8.0
Fix from $2,300 2019-03-25
Debian Linux MEDIUM 5.5
CVE-2019-3832

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header(…

Patch available
Fix from $1,600 2019-03-21
Debian Linux HIGH 7.5
CVE-2018-20175

rdesktop versions up to and including v1.8.3 contains several Integer Signedness errors that lead to Out-Of-Bounds Reads in the file mcs.c and result…

Fix: after 1.8.3
Fix from $1,950 2019-03-15
Debian Linux HIGH 7.5
CVE-2018-20178

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in the function process_demand_active() that results in a Denial of Servic…

Fix: after 1.8.3
Fix from $1,950 2019-03-15
Debian Linux MEDIUM 6.5
CVE-2019-9718

In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in Matroska format, becau…

Patch available
Fix from $1,600 2019-03-12
Debian Linux HIGH 7.8
CVE-2019-9210

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted m…

No fix yet
Fix from $1,950 2019-02-27
Debian Linux MEDIUM 5.5
CVE-2019-7665

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can…

No fix yet
Fix from $1,600 2019-02-09
Debian Linux HIGH 8.8
CVE-2019-7638

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-08
Debian Linux HIGH 8.1
CVE-2019-7635

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-08
Debian Linux HIGH 8.1
CVE-2019-7636

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-08
Debian Linux HIGH 8.1
CVE-2019-7578

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 8.8
CVE-2019-7572

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 8.8
CVE-2019-7573

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the…

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 8.8
CVE-2019-7574

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 8.8
CVE-2019-7576

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside th…

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 8.8
CVE-2019-7577

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in SDL_LoadWAV_RW in audio/SDL_wave.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 7.5
CVE-2018-8791

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpdr_process() that results in an information leak.

Fix: after 1.8.3
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.5
CVE-2018-8792

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function cssp_read_tsrequest() that results in a Denial of Service (seg…

Fix: after 1.8.3
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.5
CVE-2018-8796

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_bitmap_updates() that results in a Denial of Service (…

Fix: after 1.8.3
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.5
CVE-2018-8798

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function rdpsnd_process_ping() that results in an information leak.

Fix: after 1.8.3
Fix from $1,950 2019-02-05
Debian Linux HIGH 7.5
CVE-2018-8799

rdesktop versions up to and including v1.8.3 contain an Out-Of-Bounds Read in function process_secondary_order() that results in a Denial of Service …

Fix: after 1.8.3
Fix from $1,950 2019-02-05
Debian Linux MEDIUM 6.5
CVE-2019-1000019

libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerabil…

Fix: 3.4.0+
Fix from $1,600 2019-02-04