Vulnerability index

Browse CVEs

460 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Debian Linux HIGH 8.8
CVE-2019-9928EPSS 6%

GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a server, potentially allowing rem…

Fix: 1.16.0+
Fix from $1,950 2019-04-24
Debian Linux HIGH 7.8
CVE-2019-11221

GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.

No fix yet
Fix from $1,950 2019-04-15
Debian Linux HIGH 7.8
CVE-2019-11222

gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a crafted_drm_file.xml file.

Patch available
Fix from $1,950 2019-04-15
Debian Linux MEDIUM 5.5
CVE-2019-1788

A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior c…

Fix: after 0.101.1
Fix from $1,600 2019-04-08
Debian Linux HIGH 8.8
CVE-2019-11008

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote …

Fix: after 1.3.31
Fix from $1,950 2019-04-08
Debian Linux HIGH 8.8
CVE-2019-3856EPSS 6%

An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are …

Patch available
Fix from $1,950 2019-03-25
Debian Linux HIGH 8.8
CVE-2019-3857EPSS 6%

An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets…

Patch available
Fix from $1,950 2019-03-25
Debian Linux HIGH 8.8
CVE-2019-3863

A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive respons…

Fix: 1.8.1+
Fix from $1,950 2019-03-25
Debian Linux HIGH 8.8
CVE-2019-9956EPSS 6%

In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which allows an attacker to cause a d…

No fix yet
Fix from $1,950 2019-03-24
Debian Linux MEDIUM 5.5
CVE-2019-6454

An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer fo…

Patch available
Fix from $1,600 2019-03-21
Debian Linux CRITICAL 9.8
CVE-2018-20177EPSS 8%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() a…

Fix: after 1.8.3
Fix from $2,300 2019-03-15
Debian Linux CRITICAL 9.8
CVE-2018-20181EPSS 8%

rdesktop versions up to and including v1.8.3 contain an Integer Underflow that leads to a Heap-Based Buffer Overflow in the function seamless_process…

Fix: after 1.8.3
Fix from $2,300 2019-03-15
Debian Linux HIGH 8.8
CVE-2018-17937

gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote att…

Fix: after 3.17
Fix from $1,950 2019-03-13
Debian Linux HIGH 8.8
CVE-2019-9200

A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending…

No fix yet
Fix from $1,950 2019-02-26
Debian Linux HIGH 8.8
CVE-2019-8907

do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or…

No fix yet
Fix from $1,950 2019-02-18
Debian Linux MEDIUM 5.0
CVE-2019-8354

An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When t…

Mitigation only
Fix from $1,600 2019-02-15
Debian Linux HIGH 8.1
CVE-2019-7659

Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impa…

Fix: 2.8.75+
Fix from $1,950 2019-02-09
Debian Linux HIGH 8.8
CVE-2019-7637

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-08
Debian Linux HIGH 8.8
CVE-2019-7575

SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in MS_ADPCM_decode in audio/SDL_wave.c.

Fix: after 2.0.9
Fix from $1,950 2019-02-07
Debian Linux HIGH 7.8
CVE-2018-20760

In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because a certain -1 …

Fix: after 0.7.1
Fix from $1,950 2019-02-06
Debian Linux HIGH 7.8
CVE-2018-20763

In GPAC 0.7.1 and earlier, gf_text_get_utf8_line in media_tools/text_import.c in libgpac_static.a allows an out-of-bounds write because of missing sz…

Fix: after 0.7.1
Fix from $1,950 2019-02-06
Debian Linux CRITICAL 9.8
CVE-2018-8793EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function cssp_read_tsrequest() that results in a memory corrupti…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8794EPSS 7%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() an…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8795EPSS 7%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_update…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8797EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function process_plane() that results in a memory corruption and…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8800EPSS 7%

rdesktop versions up to and including v1.8.3 contain a Heap-Based Buffer Overflow in function ui_clip_handle_data() that results in a memory corrupti…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-20748

LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.

Fix: 0.9.12 / 3.2.1.0+
Fix from $2,300 2019-01-30
Debian Linux HIGH 8.8
CVE-2019-6245

An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_aa::not_equal, dx is assigned …

Patch available
Fix from $1,950 2019-01-13
Debian Linux CRITICAL 9.8
CVE-2018-1160EPSS 87%

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data.…

Fix: 1.2-7742-5 / 3.1.12+
Fix from $2,300 2018-12-20
Debian Linux HIGH 7.8
CVE-2018-20196

There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder…

No fix yet
Fix from $1,950 2018-12-18