Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
CRITICAL 9.1 CVE-2017-7753 An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects … Debian Linux 52.3.0 / 55.0+ Fix from $2,3002018-06-11 HIGH 7.5 CVE-2017-7754 An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefo… Debian Linux 52.2.0 / 54.0+ Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2017-5446 An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable… Debian Linux 45.9.0 / 53.0+ Fix from $2,3002018-06-11 MEDIUM 6.5 CVE-2018-11439 The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based bu… Debian Linux No fix yet Fix from $1,6002018-05-30 MEDIUM 5.5 CVE-2018-11503 The isfootnote function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer ove… Debian Linux Mitigation only Fix from $1,6002018-05-26 MEDIUM 5.5 CVE-2018-11504 The islist function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-re… Debian Linux Mitigation only Fix from $1,6002018-05-26 MEDIUM 5.5 CVE-2018-11468 The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer o… Debian Linux No fix yet Fix from $1,6002018-05-25 CRITICAL 9.1 CVE-2018-1000301EPSS 6% curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl… Debian Linux 7.2+ Fix from $2,3002018-05-24 MEDIUM 6.5 CVE-2018-10999 An issue was discovered in Exiv2 0.26. The Exiv2::Internal::PngChunk::parseTXTChunk function has a heap-based buffer over-read. Debian Linux No fix yet Fix from $1,6002018-05-12 HIGH 8.8 CVE-2018-10392 mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial … Debian Linux No fix yet Fix from $1,9502018-04-26 HIGH 7.5 CVE-2018-10393 bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read. Debian Linux Mitigation only Fix from $1,9502018-04-26 HIGH 7.5 CVE-2018-6798 An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and… Debian Linux after 5.26 Fix from $1,9502018-04-17 MEDIUM 6.5 CVE-2018-10001 The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) … Debian Linux after 3.4.2 Fix from $1,6002018-04-11 MEDIUM 6.5 CVE-2018-3838 An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially cr… Debian Linux No fix yet Fix from $1,6002018-04-10 MEDIUM 5.5 CVE-2018-3837 An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A s… Debian Linux No fix yet Fix from $1,6002018-04-10 HIGH 7.5 CVE-2018-9988 ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on inva… Debian Linux 2.1.11 / 2.7.2+ Fix from $1,9502018-04-10 HIGH 7.5 CVE-2018-9989 ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid … Debian Linux 2.1.11 / 2.7.2+ Fix from $1,9502018-04-10 MEDIUM 6.5 CVE-2018-8976 In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a c… Debian Linux Patch available Fix from $1,6002018-03-25 MEDIUM 5.5 CVE-2018-8754 The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values… Debian Linux 20180317+ Fix from $1,6002018-03-18 CRITICAL 9.1 CVE-2018-1000122EPSS 9% A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of serv… Debian Linux 7.2+ Fix from $2,3002018-03-14 MEDIUM 5.5 CVE-2018-1000085 ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Lea… Debian Linux Patch available Fix from $1,6002018-03-13 MEDIUM 6.5 CVE-2018-7875 There is a heap-based buffer over-read in the getString function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead t… Debian Linux No fix yet Fix from $1,6002018-03-08 HIGH 8.8 CVE-2018-7871 There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT16 data. A crafted input will lead to… Debian Linux No fix yet Fix from $1,9502018-03-08 MEDIUM 6.5 CVE-2018-7868 There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead to … Debian Linux No fix yet Fix from $1,6002018-03-08 MEDIUM 5.5 CVE-2018-7730 An issue was discovered in Exempi through 2.4.4. A certain case of a 0xffffffff length is mishandled in XMPFiles/source/FormatSupport/PSIR_FileWriter… Debian Linux after 2.4.4 Fix from $1,6002018-03-06 HIGH 7.1 CVE-2017-14461EPSS 17% A specially crafted email delivered over SMTP and passed on to Dovecot by MTA can trigger an out of bounds read resulting in potential sensitive info… Debian Linux Patch available Fix from $1,9502018-03-02 HIGH 8.8 CVE-2018-7550 The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU hos… Debian Linux Patch available Fix from $1,9502018-03-01 MEDIUM 6.5 CVE-2018-7557 The decode_init function in libavcodec/utvideodec.c in FFmpeg 2.8 through 3.4.2 allows remote attackers to cause a denial of service (Out of array re… Debian Linux after 3.4.2 Fix from $1,6002018-02-28 HIGH 8.8 CVE-2018-7435 An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell function. Debian Linux 1.0.5+ Fix from $1,9502018-02-23 HIGH 8.8 CVE-2018-7436 An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function. Debian Linux 1.0.5+ Fix from $1,9502018-02-23