Vulnerability index

Browse CVEs

198 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Debian Linux HIGH 7.8
CVE-2022-1923

DOS / potential heap overwrite in mkv demuxing using bzip decompression. Integer overflow in matroskademux element in bzip decompression function whi…

Fix: 1.20.3+
Fix from $1,950 2022-07-19
Debian Linux MEDIUM 5.5
CVE-2022-27114

There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large …

Patch available
Fix from $1,600 2022-05-09
Debian Linux HIGH 7.8
CVE-2021-3624

There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be exe…

No fix yet
Fix from $1,950 2022-04-18
Debian Linux CRITICAL 9.8
CVE-2022-26495

In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length …

Fix: 3.24+
Fix from $2,300 2022-03-06
Debian Linux MEDIUM 6.1
CVE-2021-20303

A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted file to be processed by OpenEXR …

Fix: 2.5.4+
Fix from $1,600 2022-03-04
Debian Linux MEDIUM 5.5
CVE-2021-20300

A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who can submit a crafted file th…

Fix: 2.5.4+
Fix from $1,600 2022-03-04
Debian Linux HIGH 7.8
CVE-2022-0545

An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing…

Fix: 2.83.19 / 2.93.8+
Fix from $1,950 2022-02-24
Debian Linux MEDIUM 6.0
CVE-2021-3607

An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handl…

Fix: 6.1.0+
Fix from $1,600 2022-02-24
Debian Linux CRITICAL 9.8
CVE-2022-25315

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

Fix: 2.4.5 / 3.1+
Fix from $2,300 2022-02-18
Debian Linux HIGH 7.5
CVE-2022-25314

In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

Fix: 2.4.5 / 3.1+
Fix from $1,950 2022-02-18
Debian Linux HIGH 7.5
CVE-2022-23990

Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

Fix: 2.4.4 / 3.1+
Fix from $1,950 2022-01-26
Debian Linux CRITICAL 9.8
CVE-2022-23852

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

Fix: 2.4.4 / 3.1+
Fix from $2,300 2022-01-24
Debian Linux HIGH 8.8
CVE-2022-22826

nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $1,950 2022-01-10
Debian Linux HIGH 8.8
CVE-2022-22827

storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $1,950 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2022-22822

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2022-22823

build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2022-22824

defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $2,300 2022-01-10
Debian Linux HIGH 8.8
CVE-2022-22825

lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

Fix: 2.4.3 / 3.1+
Fix from $1,950 2022-01-10
Debian Linux MEDIUM 5.0
CVE-2021-43784

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serializ…

Fix: 1.0.3+
Fix from $1,600 2021-12-06
Debian Linux HIGH 7.5
CVE-2021-43618

GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, …

Fix: after 6.2.1
Fix from $1,950 2021-11-15
Debian Linux HIGH 7.5
CVE-2021-41990EPSS 7%

The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signature. For example, this can…

Fix: 5.9.4+
Fix from $1,950 2021-10-18
Debian Linux HIGH 7.5
CVE-2021-41991EPSS 5%

The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with different certificates to …

Fix: 5.9.4+
Fix from $1,950 2021-10-18
Debian Linux HIGH 7.5
CVE-2021-40346EPSS 58%

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing a…

Fix: 2.0.25 / 2.2.17+
Fix from $1,950 2021-09-08
Debian Linux HIGH 7.8
CVE-2021-39254

A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NT…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux MEDIUM 5.5
CVE-2021-36058

XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Integer Overflow vulnerability potentially resulting in application-level denial of se…

Fix: after 2020.1
Fix from $1,600 2021-09-01
Debian Linux HIGH 8.8
CVE-2021-21850

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1.…

No fix yet
Fix from $1,950 2021-08-25
Debian Linux HIGH 8.8
CVE-2021-38714

In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoad…

Fix: after 1.8.5
Fix from $1,950 2021-08-24
Debian Linux HIGH 8.8
CVE-2021-21837

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library …

No fix yet
Fix from $1,950 2021-08-18
Debian Linux HIGH 8.8
CVE-2021-21859

An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.…

No fix yet
Fix from $1,950 2021-08-16
Debian Linux HIGH 7.5
CVE-2021-31292

An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (D…

Patch available
Fix from $1,950 2021-07-26