Vulnerability index

Browse CVEs

116 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Enterprise Linux HIGH 7.0
CVE-2020-1751

An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function…

Fix: 2.31+
Fix from $1,950 2020-04-17
Enterprise Linux Desktop HIGH 8.8
CVE-2020-10531

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer ove…

Fix: 10.21.0 / 80.0.3987.122+
Fix from $1,950 2020-03-12
Openstack MEDIUM 6.0
CVE-2020-1711

An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming f…

Fix: 4.2.1+
Fix from $1,600 2020-02-11
Enterprise Linux Desktop HIGH 7.8
CVE-2014-8141EPSS 7%

Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a cra…

Fix: after 6.0
Fix from $1,950 2020-01-31
Enterprise Linux Desktop HIGH 7.8
CVE-2014-8139EPSS 7%

Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafte…

Fix: after 6.0
Fix from $1,950 2020-01-31
Enterprise Linux Desktop HIGH 7.8
CVE-2014-8140EPSS 7%

Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a cr…

Fix: after 6.0
Fix from $1,950 2020-01-31
Enterprise Linux HIGH 8.8
CVE-2020-0603EPSS 20%

A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfull…

Patch available
Fix from $1,950 2020-01-14
Enterprise Linux CRITICAL 9.8
CVE-2019-14906

A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL pack…

Fix: after 2.0.9
Fix from $2,300 2020-01-07
Enterprise Linux HIGH 7.8
CVE-2019-18389

A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS use…

Fix: after 0.8.0
Fix from $1,950 2019-12-23
Enterprise Linux MEDIUM 5.5
CVE-2019-18391

A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS use…

Fix: after 0.8.0
Fix from $1,600 2019-12-23
Enterprise Linux CRITICAL 9.8
CVE-2019-19333

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits…

Patch available
Fix from $2,300 2019-12-06
Enterprise Linux CRITICAL 9.8
CVE-2019-19334

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "iden…

Patch available
Fix from $2,300 2019-12-06
Enterprise Linux HIGH 7.0
CVE-2019-9755

An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafte…

Mitigation only
Fix from $1,950 2019-06-05
Enterprise Linux MEDIUM 5.5
CVE-2019-7664

In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf in…

No fix yet
Fix from $1,600 2019-02-09
Enterprise Linux Desktop HIGH 8.8
CVE-2018-5805

A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to ca…

Fix: 0.18.8+
Fix from $1,950 2018-12-07
Enterprise Linux Desktop MEDIUM 6.5
CVE-2018-5800

An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploi…

Fix: 0.18.7+
Fix from $1,600 2018-12-07
Gluster Storage HIGH 8.8
CVE-2018-14653

The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_…

Fix: after 4.1.4
Fix from $1,950 2018-10-31
Enterprise Linux Desktop HIGH 7.8
CVE-2018-12379

When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a pote…

Fix: 60.2.0 / 62.0+
Fix from $1,950 2018-10-18
Openshift Container Platform HIGH 7.7
CVE-2018-14632

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An a…

Fix: after 3.7
Fix from $1,950 2018-09-06
Enterprise Linux MEDIUM 5.5
CVE-2018-16542

In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during e…

Fix: 9.24+
Fix from $1,600 2018-09-05
Virtualization Host HIGH 8.8
CVE-2018-10907

It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size…

Fix: 3.12.14 / 4.1.4+
Fix from $1,950 2018-09-04
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-2633

An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshin…

Fix: 1.7.2+
Fix from $1,600 2018-07-27
Enterprise Linux Desktop HIGH 7.8
CVE-2018-5002 KEVEPSS 25%

Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary …

Fix: after 29.0.0.171
Fix from $1,950 2018-07-09
Enterprise Linux Desktop HIGH 8.8
CVE-2018-5146EPSS 12%

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.…

Mitigation only
Fix from $1,950 2018-06-11
Virtualization Host CRITICAL 9.8
CVE-2018-11236EPSS 7%

stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath functi…

Fix: after 2.27
Fix from $2,300 2018-05-18
Virtualization Host HIGH 7.8
CVE-2018-11237

An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the targ…

Fix: after 2.27
Fix from $1,950 2018-05-18
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-10534

The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B…

Mitigation only
Fix from $1,600 2018-04-29
Enterprise Linux HIGH 8.8
CVE-2016-5314

Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (a…

Fix: after 4.0.6
Fix from $1,950 2018-03-12
Virtualization Host CRITICAL 9.8
CVE-2018-6485

An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier coul…

Fix: after 2.26
Fix from $2,300 2018-02-01
Enterprise Linux Desktop CRITICAL 9.8
CVE-2017-14491EPSS 85%

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafte…

Fix: after 2.77
Fix from $2,300 2017-10-04