Vulnerability index

Browse CVEs

198 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Debian Linux CRITICAL 9.1
CVE-2021-35942

The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called…

Fix: 2.31+
Fix from $2,300 2021-07-22
Debian Linux HIGH 7.8
CVE-2021-32491

A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted djvu file may lead to applicati…

Fix: after 3.5.28
Fix from $1,950 2021-06-24
Debian Linux HIGH 7.1
CVE-2018-10195

lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size…

Fix: after 0.12.20
Fix from $1,950 2021-06-02
Debian Linux MEDIUM 6.5
CVE-2021-31808EPSS 5%

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (ag…

Fix: 4.15 / 5.0.6+
Fix from $1,600 2021-05-27
Debian Linux HIGH 7.5
CVE-2021-20312

A flaw was found in ImageMagick in versions 7.0.11, where an integer overflow in WriteTHUMBNAILImage of coders/thumbnail.c may trigger undefined beha…

Fix: 7.0.11-0+
Fix from $1,950 2021-05-11
Debian Linux CRITICAL 9.8
CVE-2021-31870

An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow and a subsequent heap buffer…

Fix: 2.0.9+
Fix from $2,300 2021-04-30
Debian Linux CRITICAL 9.8
CVE-2021-31872

An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overf…

Fix: 2.0.9+
Fix from $2,300 2021-04-30
Debian Linux CRITICAL 9.8
CVE-2021-31873

An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and a subsequent heap buffer over…

Fix: 2.0.9+
Fix from $2,300 2021-04-30
Debian Linux HIGH 7.5
CVE-2021-31871

An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dereference on 64-bit systems.

Fix: 2.0.9+
Fix from $1,950 2021-04-30
Debian Linux CRITICAL 9.8
CVE-2019-25032

Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability.…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25033

Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerabil…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25034

Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25038

Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability.…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2019-25039

Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Alt…

Fix: 1.9.5+
Fix from $2,300 2021-04-27
Debian Linux CRITICAL 9.8
CVE-2021-20308

Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-…

Fix: after 1.9.11
Fix from $2,300 2021-04-05
Debian Linux MEDIUM 5.5
CVE-2021-3477

There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be …

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-31
Debian Linux MEDIUM 5.3
CVE-2021-3475

There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-30
Debian Linux MEDIUM 5.3
CVE-2021-3476

A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to Open…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-30
Debian Linux MEDIUM 5.3
CVE-2021-3474

There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHu…

Fix: 2.4.3 / 2.5.4+
Fix from $1,600 2021-03-30
Debian Linux HIGH 7.8
CVE-2020-35523

An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary co…

Fix: 4.2.0+
Fix from $1,950 2021-03-09
Debian Linux HIGH 7.8
CVE-2021-3410

A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arb…

No fix yet
Fix from $1,950 2021-02-23
Debian Linux MEDIUM 6.1
CVE-2020-35738

WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-…

Patch available
Fix from $1,600 2020-12-28
Debian Linux HIGH 7.5
CVE-2020-29361

An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit li…

Fix: after 0.23.21
Fix from $1,950 2020-12-16
Advanced Package Tool MEDIUM 5.7
CVE-2020-27350

APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc…

Fix: 1.2.32ubuntu0.2 / 1.6.12ubuntu0.2+
Fix from $1,600 2020-12-10
Debian Linux MEDIUM 5.5
CVE-2020-25676

In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo(), which are all functions in …

Fix: 6.9.10-69 / 7.0.9-0+
Fix from $1,600 2020-12-08
Debian Linux HIGH 7.8
CVE-2020-27766

A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger unde…

Fix: 6.9.10-69 / 7.0.8-69+
Fix from $1,950 2020-12-04
Debian Linux MEDIUM 5.5
CVE-2020-27770

Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to …

Fix: 6.9.10-68 / 7.0.8-68+
Fix from $1,600 2020-12-04
Debian Linux MEDIUM 5.5
CVE-2020-27762

A flaw was found in ImageMagick in coders/hdr.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined beha…

Fix: 6.9.10-68 / 7.0.8-68+
Fix from $1,600 2020-12-03
Debian Linux HIGH 7.5
CVE-2020-27813

An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection. An attacker would use this flaw to …

Fix: 1.4.1+
Fix from $1,950 2020-12-02
Debian Linux MEDIUM 5.5
CVE-2019-14562

Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.

Mitigation only
Fix from $1,600 2020-11-23