Vulnerability index

Browse CVEs

116 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Amq Broker MEDIUM 5.3
CVE-2021-4040

A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. T…

Fix: 2.19.1 / 7.10.0+
Fix from $1,600 2022-08-24
Developer Tools HIGH 7.0
CVE-2021-3697

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to …

Mitigation only
Fix from $1,950 2022-07-06
Enterprise Linux MEDIUM 6.5
CVE-2021-3611

A stack overflow vulnerability was found in the Intel HD Audio device (intel-hda) of QEMU. A malicious guest could use this flaw to crash the QEMU pr…

Fix: 7.0.0+
Fix from $1,600 2022-05-11
Enterprise Linux HIGH 7.8
CVE-2022-1304

An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code executi…

Mitigation only
Fix from $1,950 2022-04-14
Enterprise Linux HIGH 7.8
CVE-2021-3575

A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use …

Fix: after 2.4.0
Fix from $1,950 2022-03-04
Enterprise Linux MEDIUM 6.1
CVE-2021-3623

A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of…

Fix: 0.6.5 / 0.7.8+
Fix from $1,600 2022-03-02
Enterprise Linux HIGH 7.8
CVE-2021-26252

A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of s…

Patch available
Fix from $1,950 2022-02-24
Enterprise Linux CRITICAL 9.8
CVE-2021-20325

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress…

Mitigation only
Fix from $2,300 2022-02-18
Enterprise Linux MEDIUM 5.5
CVE-2022-0529

A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound wri…

No fix yet
Fix from $1,600 2022-02-09
Enterprise Linux Server Update Services For Sap Solutions HIGH 7.8
CVE-2021-4034 KEVEPSS 95%

A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileg…

Patch available
Fix from $1,950 2022-01-28
Ovirt Node HIGH 7.8
CVE-2021-45417

AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of…

Fix: after 0.17.3
Fix from $1,950 2022-01-20
Enterprise Linux HIGH 7.8
CVE-2021-33285

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow…

Fix: 2021.8.22+
Fix from $1,950 2021-09-07
Virtualization MEDIUM 6.5
CVE-2021-3634

A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. On…

Fix: 0.9.6+
Fix from $1,600 2021-08-31
Enterprise Linux CRITICAL 9.8
CVE-2021-20314

Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code executio…

Fix: 1.2.11+
Fix from $2,300 2021-08-12
Enterprise Linux HIGH 8.8
CVE-2021-3570

A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote att…

Fix: 1.5.1 / 1.6.1+
Fix from $1,950 2021-07-09
Enterprise Linux MEDIUM 5.5
CVE-2021-3569

A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SI…

Fix: 0.7.2 / 0.8.0+
Fix from $1,600 2021-06-03
Ceph Storage CRITICAL 9.8
CVE-2021-20236

A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by…

Fix: 4.3.3+
Fix from $2,300 2021-05-28
Enterprise Linux CRITICAL 9.8
CVE-2018-25011

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Enterprise Linux CRITICAL 9.8
CVE-2020-36328

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check …

Fix: 1.0.1+
Fix from $2,300 2021-05-21
Jboss Core Services HIGH 8.6
CVE-2021-3517EPSS 8%

There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be…

Fix: 2.9.11+
Fix from $1,950 2021-05-19
Enterprise Linux MEDIUM 6.0
CVE-2021-20221

An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and including qemu 4.2.0on aarch64…

Fix: after 4.2.0
Fix from $1,600 2021-05-13
Enterprise Linux MEDIUM 6.5
CVE-2021-3482

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetada…

Fix: after 0.27.3
Fix from $1,600 2021-04-08
Enterprise Linux HIGH 7.8
CVE-2021-3404

In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a h…

No fix yet
Fix from $1,950 2021-03-04
Enterprise Linux HIGH 8.2
CVE-2021-20233

A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption tha…

Fix: 2.06+
Fix from $1,950 2021-03-03
Enterprise Linux HIGH 7.6
CVE-2020-25647

A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assu…

Fix: 2.06+
Fix from $1,950 2021-03-03
Enterprise Linux MEDIUM 6.7
CVE-2020-27749

A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variab…

Fix: 2.06+
Fix from $1,600 2021-03-03
Enterprise Linux MEDIUM 6.7
CVE-2021-20225

A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling…

Fix: 2.06+
Fix from $1,600 2021-03-03
Enterprise Linux HIGH 7.5
CVE-2020-29573

sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of…

Fix: 2.23+
Fix from $1,950 2020-12-06
Enterprise Linux HIGH 7.8
CVE-2020-14382

A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on e…

Patch available
Fix from $1,950 2020-09-16
Openstack MEDIUM 5.0
CVE-2020-14364EPSS 5%

An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB pa…

Fix: 5.2.0+
Fix from $1,600 2020-08-31