Vulnerability index

Browse CVEs

87 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Codeready Linux Builder Eus MEDIUM 6.5
CVE-2023-4527

A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode v…

No fix yet
Fix from $1,600 2023-09-18
Codeready Linux Builder MEDIUM 5.5
CVE-2023-4042

A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. Th…

No fix yet
Fix from $1,600 2023-08-23
Enterprise Linux MEDIUM 5.5
CVE-2023-38559

A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a den…

Fix: 10.02.0+
Fix from $1,600 2023-08-01
Enterprise Linux MEDIUM 5.9
CVE-2022-2127

An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentica…

Fix: 4.16.10 / 4.17.9+
Fix from $1,600 2023-07-20
Enterprise Linux HIGH 7.1
CVE-2023-2977

A vulnerbility was found in OpenSC. This security flaw cause a buffer overrun vulnerability in pkcs15 cardos_have_verifyrc_package. The attacker can …

Patch available
Fix from $1,950 2023-06-01
Enterprise Linux HIGH 7.1
CVE-2023-1380EPSS 17%

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel.…

Fix: 4.14.315 / 4.19.283+
Fix from $1,950 2023-03-27
Enterprise Linux CRITICAL 9.1
CVE-2022-1587

An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. Th…

Fix: 10.40+
Fix from $2,300 2022-05-16
Enterprise Linux HIGH 7.8
CVE-2022-1304

An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code executi…

Mitigation only
Fix from $1,950 2022-04-14
Enterprise Linux MEDIUM 5.5
CVE-2022-23645

swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerab…

Fix: 0.5.3 / 0.6.2+
Fix from $1,600 2022-02-18
Enterprise Linux Server Update Services For Sap Solutions HIGH 7.8
CVE-2021-4034 KEVEPSS 95%

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg…

Patch available
Fix from $1,950 2022-01-28
Enterprise Linux HIGH 7.1
CVE-2021-4166

vim is vulnerable to Out-of-bounds Read

Fix: 8.2.3884 / 11.6.6+
Fix from $1,950 2021-12-25
Ceph Storage CRITICAL 9.1
CVE-2021-4048

An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS b…

Fix: 0.3.18+
Fix from $2,300 2021-12-08
Enterprise Linux MEDIUM 5.5
CVE-2021-3605

There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an applicatio…

Fix: 3.0.5+
Fix from $1,600 2021-08-25
Enterprise Linux HIGH 7.1
CVE-2021-3571

A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a …

Fix: 2.0.1 / 3.1.1+
Fix from $1,950 2021-07-09
Enterprise Linux CRITICAL 9.1
CVE-2018-25009

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25010

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25012

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2018-25013

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.1
CVE-2020-36331

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulne…

Fix: 1.0.1 / 14.7+
Fix from $2,300 2021-05-21
Jboss Core Services HIGH 8.6
CVE-2021-3517EPSS 8%

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be…

Fix: 2.9.11+
Fix from $1,950 2021-05-19
Enterprise Linux MEDIUM 6.0
CVE-2021-20221

An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64…

Fix: after 4.2.0
Fix from $1,600 2021-05-13
Enterprise Linux MEDIUM 5.5
CVE-2020-27824

A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input t…

Fix: 2.4.0+
Fix from $1,600 2021-05-13
Hivex MEDIUM 5.4
CVE-2021-3504

A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attack…

Fix: 1.3.20+
Fix from $1,600 2021-05-11
Openstack MEDIUM 5.0
CVE-2020-14364EPSS 5%

An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB pa…

Fix: 5.2.0+
Fix from $1,600 2020-08-31
Openstack MEDIUM 6.5
CVE-2020-10756

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echorep…

Fix: 4.3.1+
Fix from $1,600 2020-07-09
Enterprise Linux CRITICAL 9.8
CVE-2019-14906

A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL pack…

Fix: after 2.0.9
Fix from $2,300 2020-01-07
Enterprise Linux HIGH 7.1
CVE-2019-18390

An out-of-bounds read in the vrend_blit_need_swizzle function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a den…

Fix: after 0.8.0
Fix from $1,950 2019-12-23
Enterprise Linux MEDIUM 6.5
CVE-2019-19624

An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_s…

Fix: 4.1.1+
Fix from $1,600 2019-12-06
Enterprise Linux Desktop HIGH 8.8
CVE-2018-5802

An error within the "kodak_radc_load_raw()" function (internal/dcraw_common.cpp) related to the "buf" variable in LibRaw versions prior to 0.18.7 can…

Fix: 0.18.7+
Fix from $1,950 2018-12-07
Enterprise Linux Desktop HIGH 7.5
CVE-2018-15978EPSS 7%

Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 31.0.0.122
Fix from $1,950 2018-11-29