Vulnerability index

Browse CVEs

460 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Debian Linux MEDIUM 6.7
CVE-2022-20369

In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation…

Patch available
Fix from $1,600 2022-08-11
Debian Linux CRITICAL 9.8
CVE-2022-37452

Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.

Fix: 4.95+
Fix from $2,300 2022-08-07
Debian Linux CRITICAL 9.8
CVE-2022-32292

In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in receiv…

Fix: after 1.41
Fix from $2,300 2022-08-03
Debian Linux MEDIUM 5.5
CVE-2022-2598

Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100.

Fix: 9.0.0100+
Fix from $1,600 2022-08-01
Debian Linux HIGH 7.8
CVE-2022-2122

DOS / potential heap overwrite in qtdemux using zlib decompression. Integer overflow in qtdemux element in qtdemux_inflate function which causes a se…

Fix: 1.20.3+
Fix from $1,950 2022-07-19
Debian Linux HIGH 7.8
CVE-2022-1920

Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite while parsing matroska files. …

Fix: 1.20.3+
Fix from $1,950 2022-07-19
Debian Linux CRITICAL 9.8
CVE-2022-31031

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, S…

Fix: after 2.12.1
Fix from $2,300 2022-06-09
Debian Linux CRITICAL 9.8
CVE-2022-31003

Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `…

Fix: 1.13.8+
Fix from $2,300 2022-05-31
Debian Linux HIGH 7.8
CVE-2022-30789

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.

Fix: after 2021.8.22
Fix from $1,950 2022-05-26
Debian Linux HIGH 7.8
CVE-2022-1785

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.

Fix: 8.2.4977+
Fix from $1,950 2022-05-19
Debian Linux HIGH 7.8
CVE-2022-1621

Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Byp…

Fix: 8.2.4919 / 13.0+
Fix from $1,950 2022-05-10
Debian Linux HIGH 7.5
CVE-2022-30293

In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platf…

Fix: after 2.36.0
Fix from $1,950 2022-05-06
Debian Linux HIGH 7.8
CVE-2021-42529

XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code exec…

Fix: after 2021.07
Fix from $1,950 2022-05-02
Debian Linux HIGH 7.8
CVE-2021-42530

XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code exec…

Fix: after 2021.07
Fix from $1,950 2022-05-02
Debian Linux HIGH 7.8
CVE-2021-42531

XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code exec…

Fix: after 2021.07
Fix from $1,950 2022-05-02
Debian Linux HIGH 7.8
CVE-2021-46790

ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecat…

Fix: after 2021.8.22
Fix from $1,950 2022-05-02
Debian Linux HIGH 7.8
CVE-2022-27239

In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining…

Fix: 6.15+
Fix from $1,950 2022-04-27
Debian Linux CRITICAL 9.8
CVE-2022-28044

Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.

Patch available
Fix from $2,300 2022-04-15
Debian Linux CRITICAL 9.8
CVE-2022-24786

PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI…

Fix: after 2.12
Fix from $2,300 2022-04-06
Debian Linux HIGH 7.5
CVE-2022-24764

PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack buffer overflow vulnerability …

Fix: after 2.12
Fix from $1,950 2022-03-22
Debian Linux HIGH 8.8
CVE-2021-43304

Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the L…

Fix: 21.10.2.15+
Fix from $1,950 2022-03-14
Debian Linux HIGH 8.8
CVE-2021-43305

Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the L…

Fix: 21.10.2.15+
Fix from $1,950 2022-03-14
Debian Linux HIGH 7.5
CVE-2020-36518

jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

Fix: 2.12.6.1 / 2.13.2.1+
Fix from $1,950 2022-03-11
Debian Linux HIGH 7.1
CVE-2022-0891

A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bou…

Fix: after 4.3.0
Fix from $1,950 2022-03-10
Debian Linux CRITICAL 9.8
CVE-2022-26496

In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by…

Fix: 3.24+
Fix from $2,300 2022-03-06
Debian Linux HIGH 8.8
CVE-2021-44142EPSS 74%

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperabilit…

Mitigation only
Fix from $1,950 2022-02-21
Debian Linux CRITICAL 9.8
CVE-2021-43299

Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copi…

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2021-43300

Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is co…

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux CRITICAL 9.8
CVE-2021-43301

Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a buffer overflow since it is …

Fix: after 2.11.1
Fix from $2,300 2022-02-16
Debian Linux HIGH 7.8
CVE-2022-0392

Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.

Fix: 8.2.4218 / 12.6+
Fix from $1,950 2022-01-28