Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2021-36051EPSS 6%

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the …

Fix: after 2020.1
Fix from $1,950 2021-10-04
Debian Linux MEDIUM 5.5
CVE-2021-40716

XMP Toolkit SDK versions 2021.07 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.…

Fix: after 2021.07
Fix from $1,600 2021-09-29
Debian Linux HIGH 7.8
CVE-2021-32272

An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read.c. It allows an attacker to c…

Fix: 2.10.0+
Fix from $1,950 2021-09-20
Debian Linux HIGH 7.8
CVE-2021-32273

An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4read.c. It allows an attacker to…

Fix: after 2.10.0
Fix from $1,950 2021-09-20
Debian Linux HIGH 7.8
CVE-2021-32274

An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 located in sbr_qmf.c. It allows a…

Fix: after 2.10.0
Fix from $1,950 2021-09-20
Debian Linux HIGH 7.8
CVE-2021-32277

An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 located in sbr_qmf.c. It allows an…

Fix: after 2.10.0
Fix from $1,950 2021-09-20
Debian Linux HIGH 7.8
CVE-2021-32278

An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in lt_predict.c. It allows an at…

Fix: after 2.10.0
Fix from $1,950 2021-09-20
Debian Linux MEDIUM 5.5
CVE-2021-32276

An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located in output.c. It allows an att…

Fix: after 2.10.0
Fix from $1,600 2021-09-20
Debian Linux MEDIUM 5.5
CVE-2021-32280

An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() located in trans_spline.c…

Fix: 3.2.8+
Fix from $1,600 2021-09-20
Debian Linux MEDIUM 5.5
CVE-2020-21913

International Components for Unicode (ICU-20850) v66.1 was discovered to contain a use after free bug in the pkg_createWithAssemblyCode function in t…

Fix: 66.1+
Fix from $1,600 2021-09-20
Debian Linux HIGH 7.5
CVE-2021-3803

nth-check is vulnerable to Inefficient Regular Expression Complexity

Fix: 2.0.1+
Fix from $1,950 2021-09-17
Debian Linux HIGH 7.5
CVE-2021-3805

object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Fix: 0.11.8+
Fix from $1,950 2021-09-17
Debian Linux HIGH 8.8
CVE-2020-21598

libde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unweighted_pred_8_sse function, which can be exploited via a crafted a file.

No fix yet
Fix from $1,950 2021-09-16
Debian Linux MEDIUM 6.5
CVE-2020-21596

libde265 v1.0.4 contains a global buffer overflow in the decode_CABAC_bit function, which can be exploited via a crafted a file.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux MEDIUM 6.5
CVE-2020-21597

libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux MEDIUM 6.5
CVE-2020-21599

libde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zscan function, which can be exploited via a crafted a file.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux MEDIUM 5.5
CVE-2020-21533

fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux MEDIUM 5.5
CVE-2020-21534

fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux MEDIUM 5.5
CVE-2020-21535

fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux MEDIUM 5.5
CVE-2020-21529

fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux MEDIUM 5.5
CVE-2020-21530

fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux MEDIUM 5.5
CVE-2020-21531

fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux MEDIUM 5.5
CVE-2020-21532

fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.

No fix yet
Fix from $1,600 2021-09-16
Debian Linux HIGH 8.1
CVE-2021-41072

squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesyst…

Patch available
Fix from $1,950 2021-09-14
Debian Linux HIGH 7.5
CVE-2021-41054

tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and …

Fix: after 0.7.4
Fix from $1,950 2021-09-13
Debian Linux MEDIUM 6.5
CVE-2020-19144

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.

Patch available
Fix from $1,600 2021-09-09
Debian Linux MEDIUM 6.5
CVE-2020-19143

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tif_dir.c'.

Patch available
Fix from $1,600 2021-09-09
Debian Linux HIGH 7.5
CVE-2021-3761

Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An att…

Fix: 1.3.0+
Fix from $1,950 2021-09-09
Debian Linux HIGH 7.5
CVE-2021-40346EPSS 58%

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing a…

Fix: 2.0.25 / 2.2.17+
Fix from $1,950 2021-09-08
Debian Linux HIGH 7.8
CVE-2021-28701

Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain …

Mitigation only
Fix from $1,950 2021-09-08