Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Directory Server MEDIUM 5.3
CVE-2026-14940

A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted…

Mitigation only
Fix from $1,600 2026-07-07
Openshift Container Platform MEDIUM 5.9
CVE-2026-12725

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies contain…

Fix: 2.93+
Fix from $1,600 2026-06-22
Hardened Images MEDIUM 6.5
CVE-2026-9149

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negat…

Fix: after 0.7.36
Fix from $1,600 2026-05-21
Hardened Images HIGH 7.8
CVE-2026-6846

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Form…

Fix: after 2.46
Fix from $1,950 2026-04-22
Enterprise Linux HIGH 7.5
CVE-2026-5201

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation …

Mitigation only
Fix from $1,950 2026-03-31
Openshift Container Platform HIGH 8.2
CVE-2025-32990

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads ce…

Mitigation only
Fix from $1,950 2025-07-10
Openshift Container Platform MEDIUM 6.6
CVE-2025-5915

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potent…

Fix: 3.8.0+
Fix from $1,600 2025-06-09
389 Directory Server MEDIUM 5.5
CVE-2024-1062

A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.

Fix: 2.2.0+
Fix from $1,600 2024-02-12
Enterprise Linux HIGH 7.5
CVE-2023-52356

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw a…

Patch available
Fix from $1,950 2024-01-25
Enterprise Linux HIGH 7.8
CVE-2023-4692

An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesys…

Fix: 2.12+
Fix from $1,950 2023-10-25
Enterprise Linux HIGH 7.8
CVE-2023-43787

A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an intege…

Fix: 1.8.7+
Fix from $1,950 2023-10-10
Enterprise Linux MEDIUM 5.5
CVE-2022-25309

A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap…

Fix: 1.0.12+
Fix from $1,600 2022-09-06
Enterprise Linux HIGH 7.8
CVE-2020-25712

A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The …

Fix: 1.20.10+
Fix from $1,950 2020-12-15
Enterprise Linux MEDIUM 6.0
CVE-2020-14310

There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in byt…

Fix: 2.06+
Fix from $1,600 2020-07-31
Enterprise Linux MEDIUM 6.0
CVE-2020-14311

There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode siz…

Fix: 2.06+
Fix from $1,600 2020-07-31
Openstack MEDIUM 6.0
CVE-2020-1711

An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming f…

Fix: 4.2.1+
Fix from $1,600 2020-02-11
Gluster Storage HIGH 8.8
CVE-2018-14653

The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_…

Fix: after 4.1.4
Fix from $1,950 2018-10-31
Enterprise Linux Desktop HIGH 7.5
CVE-2018-1089

389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading …

Fix: 1.3.6.15 / 1.4.0.9+
Fix from $1,950 2018-05-09
Enterprise Linux HIGH 7.5
CVE-2017-2591

389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute …

Fix: 1.3.6+
Fix from $1,950 2018-04-30
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-3113 KEVEPSS 100%

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.46…

Fix: 11.2.202.468 / 13.0.0.296+
Fix from $2,300 2015-06-23