Vulnerability index

Browse CVEs

460 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Debian Linux HIGH 7.5
CVE-2023-39947

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2,…

Fix: 2.6.6 / 2.9.2+
Fix from $1,950 2023-08-11
Debian Linux HIGH 7.8
CVE-2023-21255

In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege wi…

Patch available
Fix from $1,950 2023-07-13
Debian Linux HIGH 7.5
CVE-2023-2911

If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`…

Fix: after 9.18.15
Fix from $1,950 2023-06-21
Debian Linux MEDIUM 5.5
CVE-2023-32324

OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability would allow a remote attacker …

Fix: after 2.4.2
Fix from $1,600 2023-06-01
Debian Linux HIGH 7.5
CVE-2023-32307

Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.…

Fix: 1.13.15+
Fix from $1,950 2023-05-26
Debian Linux CRITICAL 9.8
CVE-2023-28879EPSS 6%

In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in…

Fix: 10.01.0+
Fix from $2,300 2023-03-31
Debian Linux CRITICAL 9.8
CVE-2022-23122

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit…

Fix: 3.1.13+
Fix from $2,300 2023-03-28
Debian Linux CRITICAL 9.8
CVE-2022-23125

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit…

Fix: 3.1.13+
Fix from $2,300 2023-03-28
Debian Linux CRITICAL 9.8
CVE-2022-0194

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit…

Fix: 3.1.13+
Fix from $2,300 2023-03-28
Debian Linux MEDIUM 6.0
CVE-2023-0330

A vulnerability in the lsi53c895a device affects the latest version of qemu. A DMA-MMIO reentrancy problem may lead to memory corruption bugs like st…

Fix: 7.2.3+
Fix from $1,600 2023-03-06
Debian Linux HIGH 7.8
CVE-2023-25221

Libde265 v1.0.10 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function in motion.cc.

Patch available
Fix from $1,950 2023-03-01
Debian Linux HIGH 7.8
CVE-2023-0770

Stack-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.

Fix: 2.2.0+
Fix from $1,950 2023-02-09
Debian Linux MEDIUM 5.5
CVE-2022-48281

processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF…

Fix: after 4.5.0
Fix from $1,600 2023-01-23
Debian Linux HIGH 7.8
CVE-2022-47655

Libde265 1.0.9 is vulnerable to Buffer Overflow in function void put_qpel_fallback<unsigned short>

No fix yet
Fix from $1,950 2023-01-05
Debian Linux HIGH 8.1
CVE-2022-43598

Multiple memory corruption vulnerabilities exist in the IFFOutput alignment padding functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A spec…

No fix yet
Fix from $1,950 2022-12-22
Debian Linux CRITICAL 9.8
CVE-2022-41794

A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PSD file ca…

No fix yet
Fix from $2,300 2022-12-22
Debian Linux CRITICAL 9.8
CVE-2022-41837

An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Spec…

No fix yet
Fix from $2,300 2022-12-22
Debian Linux CRITICAL 9.8
CVE-2022-41838

A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially-crafted .dds…

No fix yet
Fix from $2,300 2022-12-22
Debian Linux HIGH 8.1
CVE-2022-41981

A stack-based buffer overflow vulnerability exists in the TGA file format parser of OpenImageIO v2.3.19.0. A specially-crafted targa file can lead to…

No fix yet
Fix from $1,950 2022-12-22
Debian Linux CRITICAL 9.8
CVE-2022-41639

A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A s…

No fix yet
Fix from $2,300 2022-12-22
Debian Linux HIGH 7.5
CVE-2022-45685

A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.

Fix: 1.5.2+
Fix from $1,950 2022-12-13
Debian Linux HIGH 7.5
CVE-2022-45693

Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attackers to cause a Denial of Ser…

Fix: 1.5.2+
Fix from $1,950 2022-12-13
Debian Linux CRITICAL 9.8
CVE-2022-23478

xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 cont…

Fix: 0.9.21+
Fix from $2,300 2022-12-09
Debian Linux HIGH 8.8
CVE-2022-44789

A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution …

Fix: 1.3.2+
Fix from $1,950 2022-11-23
Debian Linux HIGH 7.8
CVE-2022-45188

Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root…

Fix: after 3.1.13
Fix from $1,950 2022-11-12
Debian Linux MEDIUM 6.5
CVE-2022-43252

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_16_fallback in fallback-motion.cc. This vulnerability all…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43253

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_unweighted_pred_16_fallback in fallback-motion.cc. This vulner…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43245

Libde265 v1.0.8 was discovered to contain a segmentation violation via apply_sao_internal<unsigned short> in sao.cc. This vulnerability allows attack…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43248

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_weighted_pred_avg_16_fallback in fallback-motion.cc. This vuln…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43249

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_epel_hv_fallback<unsigned short> in fallback-motion.cc. This v…

No fix yet
Fix from $1,600 2022-11-02