Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Use of Uninitialized ResourceCWE-908 × clear
Debian Linux MEDIUM 5.3
CVE-2026-56968

GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure …

Fix: 2.2.4+
Fix from $1,600 2026-06-23
Debian Linux MEDIUM 5.5
CVE-2024-50302 KEV

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by…

Fix: 3.2 / 4.19.324+
Fix from $1,600 2024-11-19
Debian Linux CRITICAL 9.1
CVE-2024-47685

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() syzbot reported that …

Fix: 4.19.323 / 5.4.285+
Fix from $2,300 2024-10-21
Debian Linux HIGH 8.8
CVE-2022-35414

softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash. NOTE…

Fix: after 7.0.0
Fix from $1,950 2022-07-11
Debian Linux MEDIUM 6.5
CVE-2021-3545

An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. T…

Fix: after 6.0.0
Fix from $1,600 2021-06-02
Debian Linux HIGH 8.2
CVE-2020-13113

An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-afte…

Fix: 0.6.22+
Fix from $1,950 2020-05-21
Debian Linux HIGH 7.5
CVE-2019-18602

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the netw…

Fix: 1.6.24 / 1.8.5+
Fix from $1,950 2019-10-29
Debian Linux MEDIUM 5.9
CVE-2019-18603

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables…

Fix: 1.6.24 / 1.8.5+
Fix from $1,600 2019-10-29
Debian Linux HIGH 8.2
CVE-2019-17533

Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninit…

Patch available
Fix from $1,950 2019-10-13
Debian Linux HIGH 7.1
CVE-2019-13220

Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service o…

Fix: after 2019-03-04
Fix from $1,950 2019-08-15
Debian Linux HIGH 8.8
CVE-2019-13135

ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.

Fix: 6.9.10-50 / 7.0.8-50+
Fix from $1,950 2019-07-01
Debian Linux MEDIUM 5.3
CVE-2019-13117EPSS 6%

In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This c…

Patch available
Fix from $1,600 2019-07-01
Debian Linux HIGH 7.8
CVE-2018-15911

In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode ope…

Patch available
Fix from $1,950 2018-08-28
Debian Linux CRITICAL 9.8
CVE-2018-5095

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This result…

Fix: 52.6.0 / 58.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-9098

ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive infor…

Fix: 1.3.24 / 6.9.8-1+
Fix from $1,950 2017-05-19