Vulnerability index

Browse CVEs

108 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Enterprise Linux HIGH 7.8
CVE-2025-26597

A buffer overflow flaw was found in X.Org and Xwayland. If XkbChangeTypesOfKey() is called with a 0 group, it will resize the key symbols table to 0 …

Fix: 21.1.16 / 24.1.6+
Fix from $1,950 2025-02-25
Enterprise Linux MEDIUM 6.4
CVE-2023-40661

Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user …

Fix: after 0.23.0
Fix from $1,600 2023-11-06
Enterprise Linux HIGH 7.5
CVE-2023-3138

A vulnerability was found in libX11. The security flaw occurs because the functions in src/InitExt.c in libX11 do not check that the values provided …

Fix: 1.8.6+
Fix from $1,950 2023-06-28
Enterprise Linux HIGH 7.1
CVE-2023-2977

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can …

Patch available
Fix from $1,950 2023-06-01
Codeready Linux Builder HIGH 8.8
CVE-2019-8720 KEV

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution.…

Mitigation only
Fix from $1,950 2023-03-06
Enterprise Linux HIGH 7.8
CVE-2022-3715

A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.

Fix: 5.1.8+
Fix from $1,950 2023-01-05
Enterprise Linux MEDIUM 5.5
CVE-2022-25310

A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. Thi…

Fix: 1.0.12+
Fix from $1,600 2022-09-06
Enterprise Linux MEDIUM 6.5
CVE-2021-3611

A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU pr…

Fix: 7.0.0+
Fix from $1,600 2022-05-11
Enterprise Linux CRITICAL 9.8
CVE-2021-20325

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress…

Mitigation only
Fix from $2,300 2022-02-18
Enterprise Linux MEDIUM 5.5
CVE-2021-3605

There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an applicatio…

Fix: 3.0.5+
Fix from $1,600 2021-08-25
Enterprise Linux HIGH 8.8
CVE-2021-3570

A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote att…

Fix: 1.5.1 / 1.6.1+
Fix from $1,950 2021-07-09
Enterprise Linux HIGH 7.1
CVE-2021-3571

A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a …

Fix: 2.0.1 / 3.1.1+
Fix from $1,950 2021-07-09
Enterprise Linux MEDIUM 5.5
CVE-2021-3598

There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an…

Fix: 3.0.5+
Fix from $1,600 2021-07-06
Libvirt MEDIUM 6.5
CVE-2021-3559

A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with a PCI device and driver that…

Fix: 7.0.0+
Fix from $1,600 2021-05-24
Enterprise Linux MEDIUM 5.7
CVE-2021-3409

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pr…

Fix: after 5.2.0
Fix from $1,600 2021-03-23
Enterprise Linux MEDIUM 5.5
CVE-2020-35521

A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of servi…

Fix: 4.2.0+
Fix from $1,600 2021-03-09
Enterprise Linux HIGH 7.8
CVE-2021-3404

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a h…

No fix yet
Fix from $1,950 2021-03-04
Enterprise Linux HIGH 7.8
CVE-2017-5332

The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cau…

Patch available
Fix from $1,950 2019-11-04
Enterprise Linux HIGH 7.8
CVE-2012-6711

A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment …

Fix: after 4.3
Fix from $1,950 2019-06-18
Satellite HIGH 7.5
CVE-2019-10245

In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causi…

Fix: 0.14.0+
Fix from $1,950 2019-04-19
Satellite CRITICAL 9.8
CVE-2018-12547

In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects exis…

Fix: 0.12.0+
Fix from $2,300 2019-02-11
Gluster Storage MEDIUM 6.5
CVE-2018-14652

The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling t…

Fix: after 4.1.8
Fix from $1,600 2018-10-31
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-12376

Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enoug…

Mitigation only
Fix from $2,300 2018-10-18
Enterprise Linux Desktop HIGH 8.8
CVE-2018-12359

A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be …

Mitigation only
Fix from $1,950 2018-10-18
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-15416

Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafte…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-15101

A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a den…

Fix: 2.5.4+
Fix from $2,300 2018-07-27
Enterprise Linux MEDIUM 5.5
CVE-2018-10872

A flaw was found in the way the Linux kernel handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During th…

Patch available
Fix from $1,600 2018-07-10
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-2668

389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote…

Fix: 1.3.5.17 / 1.3.6.10+
Fix from $1,600 2018-06-22
Virtualization Host HIGH 7.8
CVE-2018-5848

In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_le…

Patch available
Fix from $1,950 2018-06-12
Enterprise Linux Desktop CRITICAL 9.8
CVE-2018-5183

Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and…

Mitigation only
Fix from $2,300 2018-06-11