Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
HIGH 8.1 CVE-2020-18771 Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information … Debian Linux No fix yet Fix from $1,9502021-08-23 HIGH 7.5 CVE-2020-36426 An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte). Debian Linux 2.7.17 / 2.16.8+ Fix from $1,9502021-07-19 HIGH 7.8 CVE-2021-32492 A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via crafted djvu file may lead to appl… Debian Linux after 3.5.28 Fix from $1,9502021-06-24 CRITICAL 9.1 CVE-2020-36330 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this … Debian Linux 1.0.1 / 14.7+ Fix from $2,3002021-05-21 HIGH 7.5 CVE-2020-27840 A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces … Debian Linux 4.12.13 / 4.13.6+ Fix from $1,9502021-05-12 HIGH 7.5 CVE-2021-20277 A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a… Debian Linux 4.12.13 / 4.13.6+ Fix from $1,9502021-05-12 CRITICAL 9.8 CVE-2021-25216EPSS 82% In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition,… Debian Linux 1.0.1.1 / 9.11.31+ Fix from $2,3002021-04-29 MEDIUM 6.5 CVE-2021-31348 An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling while parsing crafted XML fil… Debian Linux Patch available Fix from $1,6002021-04-16 MEDIUM 5.5 CVE-2021-3477 There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be … Debian Linux 2.4.3 / 2.5.4+ Fix from $1,6002021-03-31 HIGH 7.5 CVE-2020-36281 Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c. Debian Linux 1.80.0+ Fix from $1,9502021-03-12 HIGH 7.5 CVE-2021-20275 A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service. Debian Linux 3.0.32+ Fix from $1,9502021-03-09 CRITICAL 9.8 CVE-2020-35636 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h SNC_io_parser::re… Debian Linux No fix yet Fix from $2,3002021-03-04 HIGH 7.5 CVE-2020-36223 A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service… Debian Linux 2.4.57 / 10.14.6+ Fix from $1,9502021-01-26 MEDIUM 5.4 CVE-2020-14410 SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafte… Debian Linux after 2.0.20 Fix from $1,6002021-01-19 MEDIUM 5.5 CVE-2020-25665 The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() because it needs to be offset by 2… Debian Linux 6.9.10-68 / 7.0.8-68+ Fix from $1,6002020-12-08 MEDIUM 5.0 CVE-2020-25624 hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver. Debian Linux Patch available Fix from $1,6002020-11-30 MEDIUM 6.5 CVE-2020-28241 libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c. Debian Linux 1.4.3+ Fix from $1,6002020-11-06 MEDIUM 5.5 CVE-2020-0427 In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no … Debian Linux Patch available Fix from $1,6002020-09-17 MEDIUM 6.5 CVE-2020-24977 GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixe… Debian Linux Patch available Fix from $1,6002020-09-04 MEDIUM 6.5 CVE-2020-8244 A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that… Debian Linux 1.2.3 / 2.2.1+ Fix from $1,6002020-08-30 MEDIUM 5.3 CVE-2020-17507 An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-r… Debian Linux 5.15.1+ Fix from $1,6002020-08-12 HIGH 7.5 CVE-2020-12673EPSS 6% In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read. Debian Linux 2.3.11.3+ Fix from $1,9502020-08-12 HIGH 7.5 CVE-2020-12674EPSS 6% In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled. Debian Linux 2.3.11.3+ Fix from $1,9502020-08-12 HIGH 7.5 CVE-2020-15890 LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled. Debian Linux after 2.0.5 Fix from $1,9502020-07-21 CRITICAL 9.1 CVE-2020-15472 In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated … Debian Linux after 3.2 Fix from $2,3002020-07-01 HIGH 7.5 CVE-2020-15476 In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c. Debian Linux after 3.2 Fix from $1,9502020-07-01 HIGH 7.5 CVE-2020-14148 The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function. Debian Linux after 25.0 Fix from $1,9502020-06-15 MEDIUM 6.5 CVE-2020-0182 In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information d… Debian Linux Patch available Fix from $1,6002020-06-11 MEDIUM 5.5 CVE-2020-11089 In FreeRDP before 2.1.0, there is an out-of-bound read in irp functions (parallel_process_irp_create, serial_process_irp_create, drive_process_irp_wr… Debian Linux 2.1.0+ Fix from $1,6002020-05-29 MEDIUM 5.4 CVE-2020-11086 In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_challenge that reads up to 28 bytes out-of-bound to… Debian Linux 2.1.0+ Fix from $1,6002020-05-29