Vulnerability index

Browse CVEs

460 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Debian Linux HIGH 7.8
CVE-2022-0361

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4215 / 12.6+
Fix from $1,950 2022-01-26
Debian Linux HIGH 7.8
CVE-2022-0359

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4214 / 12.6+
Fix from $1,950 2022-01-26
Debian Linux CRITICAL 9.8
CVE-2022-0318

Heap-based Buffer Overflow in vim/vim prior to 8.2.

Fix: 8.2.4151 / 13.0+
Fix from $2,300 2022-01-21
Debian Linux CRITICAL 9.8
CVE-2021-33912EPSS 10%

libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated …

Fix: 1.2.11+
Fix from $2,300 2022-01-19
Debian Linux HIGH 7.8
CVE-2022-0261

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4120 / 13.0+
Fix from $1,950 2022-01-18
Debian Linux MEDIUM 6.6
CVE-2022-0213

vim is vulnerable to Heap-based Buffer Overflow

Fix: 8.2+
Fix from $1,600 2022-01-14
Debian Linux MEDIUM 5.5
CVE-2021-37530

A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.

Fix: after 3.2.8a
Fix from $1,600 2022-01-12
Debian Linux MEDIUM 5.5
CVE-2021-36410

A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running program dec265.

No fix yet
Fix from $1,600 2022-01-10
Debian Linux HIGH 7.8
CVE-2021-43579EPSS 7%

A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linki…

Fix: after 1.9.13
Fix from $1,950 2022-01-10
Debian Linux MEDIUM 5.9
CVE-2022-22707EPSS 9%

In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes repr…

Fix: after 1.4.63
Fix from $1,600 2022-01-06
Debian Linux MEDIUM 5.5
CVE-2021-45943

GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and …

Fix: after 3.4.0
Fix from $1,600 2022-01-01
Debian Linux MEDIUM 5.5
CVE-2021-45949

Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).

Fix: after 9.54.0
Fix from $1,600 2022-01-01
Debian Linux HIGH 7.8
CVE-2021-45909

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to writ…

No fix yet
Fix from $1,950 2021-12-28
Debian Linux HIGH 7.8
CVE-2021-45910

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside …

No fix yet
Fix from $1,950 2021-12-28
Debian Linux HIGH 7.8
CVE-2021-45911

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attacker to write 2 bytes outside t…

No fix yet
Fix from $1,950 2021-12-28
Debian Linux CRITICAL 9.8
CVE-2021-40393

An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a…

No fix yet
Fix from $2,300 2021-12-22
Debian Linux CRITICAL 9.8
CVE-2021-40394

An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) a…

No fix yet
Fix from $2,300 2021-12-22
Debian Linux HIGH 8.8
CVE-2019-8922

A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destin…

Fix: after 5.48
Fix from $1,950 2021-11-29
Debian Linux CRITICAL 9.8
CVE-2021-44143

A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted ma…

Fix: after 1.4.3
Fix from $2,300 2021-11-22
Debian Linux HIGH 8.8
CVE-2021-21898

A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-cra…

No fix yet
Fix from $1,950 2021-11-19
Debian Linux CRITICAL 9.8
CVE-2021-40391

An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forke…

No fix yet
Fix from $2,300 2021-11-19
Debian Linux HIGH 7.5
CVE-2021-43174

NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding ca…

Fix: 0.10.2+
Fix from $1,950 2021-11-09
Debian Linux HIGH 7.8
CVE-2021-32272

An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to c…

Fix: 2.10.0+
Fix from $1,950 2021-09-20
Debian Linux HIGH 7.8
CVE-2021-32273

An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4read.c. It allows an attacker to…

Fix: after 2.10.0
Fix from $1,950 2021-09-20
Debian Linux HIGH 7.8
CVE-2021-32274

An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 located in sbr_qmf.c. It allows a…

Fix: after 2.10.0
Fix from $1,950 2021-09-20
Debian Linux HIGH 7.8
CVE-2021-32277

An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 located in sbr_qmf.c. It allows an…

Fix: after 2.10.0
Fix from $1,950 2021-09-20
Debian Linux HIGH 7.8
CVE-2021-32278

An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It allows an at…

Fix: after 2.10.0
Fix from $1,950 2021-09-20
Debian Linux HIGH 8.8
CVE-2020-21598

libde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unweighted_pred_8_sse function, which can be exploited via a crafted a file.

No fix yet
Fix from $1,950 2021-09-16
Debian Linux MEDIUM 6.5
CVE-2020-21597

libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux MEDIUM 6.5
CVE-2020-21599

libde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zscan function, which can be exploited via a crafted a file.

No fix yet
Fix from $1,600 2021-09-16