Vulnerability index

Browse CVEs

87 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Enterprise Linux HIGH 7.8
CVE-2018-19214

Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.

Patch available
Fix from $1,950 2018-11-12
Enterprise Linux HIGH 7.8
CVE-2018-19215

Netwide Assembler (NASM) 2.14rc16 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for the special cases of the % and $ and !…

No fix yet
Fix from $1,950 2018-11-12
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-12366

An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak p…

Mitigation only
Fix from $1,600 2018-10-18
Enterprise Linux Desktop HIGH 7.5
CVE-2018-12826EPSS 7%

Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 30.0.0.154
Fix from $1,950 2018-08-29
Enterprise Linux Desktop HIGH 7.5
CVE-2018-12827EPSS 32%

Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 30.0.0.154
Fix from $1,950 2018-08-29
Enterprise Linux Desktop MEDIUM 5.9
CVE-2018-12824EPSS 11%

Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

Fix: after 30.0.0.154
Fix from $1,600 2018-08-29
Jboss Core Services MEDIUM 6.5
CVE-2016-9598

libxml2, as used in Red Hat JBoss Core Services, allows context-dependent attackers to cause a denial of service (out-of-bounds read and application …

Fix: 2.9.4+
Fix from $1,600 2018-08-16
Enterprise Linux Desktop HIGH 7.8
CVE-2016-9583

An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.

Fix: 2.0.6+
Fix from $1,950 2018-08-01
Enterprise Linux Desktop HIGH 8.1
CVE-2016-9573

An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another fo…

Patch available
Fix from $1,950 2018-08-01
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-2633

An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshin…

Fix: 1.7.2+
Fix from $1,600 2018-07-27
Enterprise Linux Desktop HIGH 7.5
CVE-2018-5008EPSS 7%

Adobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclo…

Fix: after 30.0.0.113
Fix from $1,950 2018-07-20
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-5001EPSS 13%

Adobe Flash Player versions 29.0.0.171 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclo…

Fix: after 29.0.0.171
Fix from $1,600 2018-07-09
Enterprise Linux Desktop CRITICAL 9.1
CVE-2017-7758

An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vu…

Fix: 52.2.0 / 54.0+
Fix from $2,300 2018-06-11
Ansible Tower MEDIUM 6.5
CVE-2018-10767

There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 beca…

Fix: after 0.3.0
Fix from $1,600 2018-05-06
Ansible Tower MEDIUM 6.5
CVE-2018-10733

There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a rem…

Fix: after 0.3.0
Fix from $1,600 2018-05-04
Enterprise Linux HIGH 7.5
CVE-2017-2591

389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute …

Fix: 1.3.6+
Fix from $1,950 2018-04-30
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-10372

process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application…

No fix yet
Fix from $1,600 2018-04-25
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-7858

Quick Emulator (aka QEMU), when built with the Cirrus CLGD 54xx VGA Emulator support, allows local guest OS privileged users to cause a denial of ser…

Fix: after 2.11.2
Fix from $1,600 2018-03-12
Enterprise Linux Desktop HIGH 7.5
CVE-2018-1054

An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A rem…

Fix: after 1.4.0.6
Fix from $1,950 2018-03-07
Enterprise Linux Desktop HIGH 7.5
CVE-2018-4871EPSS 6%

An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data …

Fix: after 28.0.0.126
Fix from $1,950 2018-01-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-3112EPSS 6%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-3114EPSS 6%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-11213EPSS 7%

An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data…

Fix: after 27.0.0.183
Fix from $2,300 2017-12-09
Enterprise Linux Desktop HIGH 7.5
CVE-2014-9657EPSS 5%

The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers…

Patch available
Fix from $1,950 2015-02-08
Shim MEDIUM 5.0
CVE-2014-3675

Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.

Fix: 0.8+
Fix from $1,600 2014-10-22
Enterprise Linux Desktop MEDIUM 5.0
CVE-2014-4341EPSS 7%

MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting in…

Patch available
Fix from $1,600 2014-07-20
Libpng MEDIUM 5.0
CVE-2004-0421

The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image fil…

Patch available
Fix from $1,600 2004-08-18