Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux MEDIUM 6.5
CVE-2019-7149

A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cau…

Patch available
Fix from $1,600 2019-01-29
Debian Linux MEDIUM 5.5
CVE-2019-7150

An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segm…

Patch available
Fix from $1,600 2019-01-29
Debian Linux HIGH 7.1
CVE-2019-6956

An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. It is a buffer over-read in ps_mix_phase in libfaad/ps_dec.c.

Fix: 2.9.0+
Fix from $1,950 2019-01-25
Debian Linux CRITICAL 9.8
CVE-2018-20721

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address c…

Fix: 0.9.1+
Fix from $2,300 2019-01-16
Debian Linux MEDIUM 6.5
CVE-2018-20570

jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

No fix yet
Fix from $1,600 2018-12-28
Debian Linux MEDIUM 6.5
CVE-2018-20430

GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRAC…

Fix: after 1.8
Fix from $1,600 2018-12-24
Debian Linux MEDIUM 5.3
CVE-2018-20185

In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which a…

Patch available
Fix from $1,600 2018-12-17
Debian Linux MEDIUM 6.5
CVE-2018-19758

There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.

No fix yet
Fix from $1,600 2018-11-30
Debian Linux MEDIUM 6.5
CVE-2018-19497

In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows atta…

Fix: after 4.6.4
Fix from $1,600 2018-11-29
Debian Linux HIGH 8.1
CVE-2018-19662

An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of servic…

Patch available
Fix from $1,950 2018-11-29
Debian Linux MEDIUM 6.5
CVE-2018-19661

An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of servic…

No fix yet
Fix from $1,600 2018-11-29
Debian Linux MEDIUM 6.5
CVE-2018-19535

In Exiv2 0.26 and previous versions, PngChunk::readRawProfile in pngchunk_int.cpp may cause a denial of service (application crash due to a heap-base…

Fix: after 0.26
Fix from $1,600 2018-11-26
Debian Linux MEDIUM 6.5
CVE-2018-19107

In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-bas…

Patch available
Fix from $1,600 2018-11-08
Debian Linux MEDIUM 5.5
CVE-2018-18605

A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka …

No fix yet
Fix from $1,600 2018-10-23
Debian Linux MEDIUM 5.5
CVE-2018-15378

A vulnerability in ClamAV versions prior to 0.100.2 could allow an attacker to cause a denial of service (DoS) condition. The vulnerability is due to…

Fix: 0.100.2+
Fix from $1,600 2018-10-15
Debian Linux MEDIUM 6.5
CVE-2018-18025

In ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers to cause a d…

Patch available
Fix from $1,600 2018-10-07
Debian Linux HIGH 8.8
CVE-2018-16430

GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.

Fix: after 1.7
Fix from $1,950 2018-09-04
Debian Linux MEDIUM 5.5
CVE-2018-16062

dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer…

Fix: 0.174+
Fix from $1,600 2018-08-29
Debian Linux HIGH 7.5
CVE-2018-15501

In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packe…

Fix: 0.26.6 / 0.27.4+
Fix from $1,950 2018-08-18
Debian Linux CRITICAL 9.8
CVE-2018-1999010

FFmpeg before commit cced03dd667a5df6df8fd40d8de0bff477ee02e8 contains multiple out of array access vulnerabilities in the mms protocol that can resu…

Fix: 3.4.3+
Fix from $2,300 2018-07-23
Debian Linux HIGH 8.8
CVE-2018-14447

trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.

Patch available
Fix from $1,950 2018-07-20
Debian Linux HIGH 8.1
CVE-2018-10887

A flaw was found in libgit2 before version 0.27.3. It has been discovered that an unexpected sign extension in git_delta_apply function in delta.c fi…

Fix: 0.27.3+
Fix from $1,950 2018-07-10
Debian Linux MEDIUM 6.5
CVE-2018-10888

A flaw was found in libgit2 before version 0.27.3. A missing check in git_delta_apply function in delta.c file, may lead to an out-of-bound read whil…

Fix: 0.27.3+
Fix from $1,600 2018-07-10
Debian Linux HIGH 8.1
CVE-2018-13300

In FFmpeg 3.2 and 4.0.1, an improper argument (AVCodecParameters) passed to the avpriv_request_sample function in the handle_eac3 function in libavfo…

Patch available
Fix from $1,950 2018-07-05
Debian Linux CRITICAL 9.8
CVE-2018-13005

An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.

No fix yet
Fix from $2,300 2018-06-29
Debian Linux CRITICAL 9.8
CVE-2018-13006

An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.

Patch available
Fix from $2,300 2018-06-29
Debian Linux MEDIUM 5.5
CVE-2018-12495

The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer ove…

No fix yet
Fix from $1,600 2018-06-15
Debian Linux HIGH 8.8
CVE-2018-12264

Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.…

No fix yet
Fix from $1,950 2018-06-13
Debian Linux HIGH 8.8
CVE-2018-12265

Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.

No fix yet
Fix from $1,950 2018-06-13
Debian Linux CRITICAL 9.1
CVE-2017-5465EPSS 19%

An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory bein…

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11