Vulnerability index

Browse CVEs

460 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Debian Linux MEDIUM 6.5
CVE-2022-43250

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_0_0_fallback_16 in fallback-motion.cc. This vulnerability…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43239

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_chroma<unsigned short> in motion.cc. This vulnerability allows …

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43240

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_qpel_h_2_v_1_sse in sse-motion.cc. This vulnerabi…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43241

Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_v_3_8_sse in sse-motion.cc. This vulnerability allows attackers …

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43242

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_luma<unsigned char> in motion.cc. This vulnerability allows att…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43243

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_weighted_pred_avg_8_sse in sse-motion.cc. This vulnera…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43244

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via put_qpel_fallback<unsigned short> in fallback-motion.cc. This vuln…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43235

Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_epel_pixels_8_sse in sse-motion.cc. This vulnerab…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43236

Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via put_qpel_fallback<unsigned short> in fallback-motion.cc. This vul…

No fix yet
Fix from $1,600 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-43237

Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via void put_epel_hv_fallback<unsigned short> in fallback-motion.cc. …

No fix yet
Fix from $1,600 2022-11-02
Debian Linux HIGH 8.1
CVE-2021-37789

stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.

No fix yet
Fix from $1,950 2022-11-02
Debian Linux MEDIUM 6.5
CVE-2022-3598

LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-servi…

Fix: after 4.4.0
Fix from $1,600 2022-10-21
Debian Linux MEDIUM 6.5
CVE-2022-3626

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections, tools/tiffcrop.c:7619, allo…

Fix: after 4.4.0
Fix from $1,600 2022-10-21
Debian Linux MEDIUM 6.5
CVE-2022-3627

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6860, allowi…

Fix: after 4.4.0
Fix from $1,600 2022-10-21
Debian Linux MEDIUM 6.5
CVE-2022-3597

LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, tools/tiffcrop.c:6826, allowi…

Fix: after 4.4.0
Fix from $1,600 2022-10-21
Debian Linux MEDIUM 5.5
CVE-2022-3570

Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe or out of bounds memory acces…

Fix: after 4.4.0
Fix from $1,600 2022-10-21
Debian Linux HIGH 7.8
CVE-2022-1270

In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.

No fix yet
Fix from $1,950 2022-09-28
Debian Linux HIGH 7.5
CVE-2022-40149

Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user suppl…

Fix: after 1.4.0
Fix from $1,950 2022-09-16
Debian Linux MEDIUM 5.5
CVE-2022-38855

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemux/demux_mov.c. This affects m…

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38858

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer…

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38861

The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c.

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38863

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and …

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38864

Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencod…

No fix yet
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 5.5
CVE-2022-38866

Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38…

Mitigation only
Fix from $1,600 2022-09-15
Debian Linux MEDIUM 6.5
CVE-2022-38749

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …

Fix: 1.31+
Fix from $1,600 2022-09-05
Debian Linux MEDIUM 6.5
CVE-2022-38751

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …

Fix: 1.31+
Fix from $1,600 2022-09-05
Debian Linux MEDIUM 5.5
CVE-2022-38750

Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, …

Fix: 1.31+
Fix from $1,600 2022-09-05
Debian Linux MEDIUM 5.5
CVE-2020-35530

In LibRaw, there is an out-of-bounds write vulnerability within the "new_node()" function (libraw\src\x3f\x3f_utils_patched.cpp) that can be triggere…

Patch available
Fix from $1,600 2022-09-01
Debian Linux MEDIUM 5.5
CVE-2021-4214

A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG…

No fix yet
Fix from $1,600 2022-08-24
Debian Linux HIGH 7.5
CVE-2021-20298

A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed by OpenEXR, to exhaust all me…

Fix: after 2.5.7
Fix from $1,950 2022-08-23