Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2021-39255

A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39256

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_inode_lookup_by_name in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39258

A crafted NTFS image can cause out-of-bounds reads in ntfs_attr_find and ntfs_external_attr_find in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39259

A crafted NTFS image can trigger an out-of-bounds access, caused by an unsanitized attribute length in ntfs_inode_lookup_by_name, in NTFS-3G < 2021.8…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39260

A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39261

A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39262

A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39263

A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux MEDIUM 5.5
CVE-2021-39257

A crafted NTFS image with an unallocated bitmap can lead to a endless recursive function call chain (starting from ntfs_attr_pwrite), causing stack c…

Fix: 2021.8.22+
Fix from $1,600 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-33286

In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow for …

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-33287

In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur …

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-35266

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-35267

NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or e…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39251

A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39252

A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39253

A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-39254

A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NT…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.5
CVE-2020-19131

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".

Patch available
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-33289

In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for cod…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-35268

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.8
CVE-2021-35269

NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overf…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Debian Linux HIGH 7.5
CVE-2021-40516

WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in…

Fix: 3.2.1+
Fix from $1,950 2021-09-05
Debian Linux MEDIUM 6.5
CVE-2021-40491

The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. Th…

Fix: 2.2+
Fix from $1,600 2021-09-03
Debian Linux HIGH 7.8
CVE-2021-39847EPSS 5%

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially resulting in arbitrary code execu…

Fix: after 2020.1
Fix from $1,950 2021-09-01
Debian Linux HIGH 7.8
CVE-2021-36064

XMP Toolkit version 2020.1 (and earlier) is affected by a Buffer Underflow vulnerability which could result in arbitrary code execution in the contex…

Fix: after 2020.1
Fix from $1,950 2021-09-01
Debian Linux MEDIUM 5.5
CVE-2021-36058

XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Integer Overflow vulnerability potentially resulting in application-level denial of se…

Fix: after 2020.1
Fix from $1,600 2021-09-01
Debian Linux HIGH 7.8
CVE-2021-36046

XMP Toolkit version 2020.1 (and earlier) is affected by a memory corruption vulnerability, potentially resulting in arbitrary code execution in the c…

Fix: after 2020.1
Fix from $1,950 2021-09-01
Debian Linux HIGH 7.8
CVE-2021-36047

XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execut…

Fix: after 2020.1
Fix from $1,950 2021-09-01
Debian Linux HIGH 7.8
CVE-2021-36048

XMP Toolkit SDK version 2020.1 (and earlier) is affected by an Improper Input Validation vulnerability potentially resulting in arbitrary code execut…

Fix: after 2020.1
Fix from $1,950 2021-09-01
Debian Linux HIGH 7.8
CVE-2021-36050EPSS 5%

XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arbitrary code execution in the …

Fix: after 2020.1
Fix from $1,950 2021-09-01