Vulnerability index

Browse CVEs

460 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Debian Linux MEDIUM 5.5
CVE-2020-16291

A buffer overflow vulnerability in contrib/gdevdj9.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of ser…

Fix: 9.52+
Fix from $1,600 2020-08-13
Debian Linux MEDIUM 6.8
CVE-2020-0256

In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privil…

Mitigation only
Fix from $1,600 2020-08-11
Debian Linux MEDIUM 5.3
CVE-2020-15863

hw/net/xgmac.c in the XGMAC Ethernet controller in QEMU before 07-20-2020 has a buffer overflow. This occurs during packet transmission and affects t…

Fix: after 5.0.0
Fix from $1,600 2020-07-28
Debian Linux CRITICAL 9.8
CVE-2020-15866

mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can b…

Fix: after 2.1.1
Fix from $2,300 2020-07-21
Debian Linux HIGH 7.4
CVE-2020-11061

In Bareos Director less than or equal to 16.2.10, 17.2.9, 18.2.8, and 19.2.7, a heap overflow allows a malicious client to corrupt the director's mem…

Fix: after 19.2.7
Fix from $1,950 2020-07-10
Debian Linux HIGH 7.8
CVE-2020-13428

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS…

Fix: 3.0.11+
Fix from $1,950 2020-06-08
Debian Linux HIGH 7.5
CVE-2020-12672

GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.

Fix: after 1.3.35
Fix from $1,950 2020-05-06
Debian Linux CRITICAL 9.8
CVE-2020-12268

jbig2_image_compose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.

Fix: 0.18+
Fix from $2,300 2020-04-27
Debian Linux CRITICAL 9.8
CVE-2019-12519EPSS 7%

An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function …

Fix: after 5.0.1
Fix from $2,300 2020-04-15
Debian Linux HIGH 8.8
CVE-2020-11100EPSS 61%

In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a…

Fix: 2.1.4+
Fix from $1,950 2020-04-02
Debian Linux CRITICAL 9.8
CVE-2020-10938EPSS 5%

GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.

Fix: 1.3.35+
Fix from $2,300 2020-03-24
Debian Linux HIGH 7.8
CVE-2019-20326

A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.…

Fix: 2.4.5 / 3.8.3+
Fix from $1,950 2020-03-16
Debian Linux CRITICAL 9.8
CVE-2020-10232

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaf…

Fix: after 4.8.0
Fix from $2,300 2020-03-09
Debian Linux HIGH 7.8
CVE-2020-9549

In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document.

Fix: after 0.19
Fix from $1,950 2020-03-02
Debian Linux HIGH 7.5
CVE-2015-9542

add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based b…

Patch available
Fix from $1,950 2020-02-24
Debian Linux HIGH 7.8
CVE-2019-18634EPSS 19%

In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwf…

Fix: 1.8.26+
Fix from $1,950 2020-01-29
Debian Linux HIGH 8.8
CVE-2020-8112

opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different…

No fix yet
Fix from $1,950 2020-01-28
Debian Linux MEDIUM 5.6
CVE-2020-7039

tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a h…

Patch available
Fix from $1,600 2020-01-16
Debian Linux MEDIUM 5.5
CVE-2019-20208

dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow.

Fix: after 0.8.0
Fix from $1,600 2020-01-02
Debian Linux MEDIUM 5.5
CVE-2019-20161

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_Waterm…

No fix yet
Fix from $1,600 2019-12-31
Debian Linux MEDIUM 5.5
CVE-2019-20162

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_e…

No fix yet
Fix from $1,600 2019-12-31
Debian Linux CRITICAL 9.8
CVE-2019-19951

In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.

Patch available
Fix from $2,300 2019-12-24
Debian Linux HIGH 7.5
CVE-2019-19906EPSS 8%

cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP pa…

Patch available
Fix from $1,950 2019-12-19
Debian Linux HIGH 8.1
CVE-2019-17358

Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An auth…

Fix: after 1.2.7
Fix from $1,950 2019-12-12
Debian Linux HIGH 7.5
CVE-2019-5815

Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit heap corruption via crafted X…

Fix: 1.1.33+
Fix from $1,950 2019-12-11
Debian Linux HIGH 7.8
CVE-2019-19630

HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a cr…

No fix yet
Fix from $1,950 2019-12-08
Debian Linux HIGH 8.8
CVE-2011-3630

Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are pr…

Fix: 0.1.2+
Fix from $1,950 2019-11-26
Debian Linux HIGH 8.8
CVE-2019-5087

An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An i…

No fix yet
Fix from $1,950 2019-11-21
Debian Linux HIGH 8.8
CVE-2019-5086

An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.…

No fix yet
Fix from $1,950 2019-11-21
Debian Linux HIGH 7.8
CVE-2014-5439

Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutabl…

Fix: after 0.3.7
Fix from $1,950 2019-11-19