Vulnerability index

Browse CVEs

116 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
HIGH 7.0 CVE-2020-1751 An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function… Enterprise Linux 2.31+ Fix from $1,9502020-04-17 HIGH 8.8 CVE-2020-10531 An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer ove… Enterprise Linux Desktop 10.21.0 / 80.0.3987.122+ Fix from $1,9502020-03-12 MEDIUM 6.0 CVE-2020-1711 An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming f… Openstack 4.2.1+ Fix from $1,6002020-02-11 HIGH 7.8 CVE-2014-8141EPSS 7% Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a cra… Enterprise Linux Desktop after 6.0 Fix from $1,9502020-01-31 HIGH 7.8 CVE-2014-8139EPSS 7% Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafte… Enterprise Linux Desktop after 6.0 Fix from $1,9502020-01-31 HIGH 7.8 CVE-2014-8140EPSS 7% Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a cr… Enterprise Linux Desktop after 6.0 Fix from $1,9502020-01-31 HIGH 8.8 CVE-2020-0603EPSS 20% A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfull… Enterprise Linux Patch available Fix from $1,9502020-01-14 CRITICAL 9.8 CVE-2019-14906 A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL pack… Enterprise Linux after 2.0.9 Fix from $2,3002020-01-07 HIGH 7.8 CVE-2019-18389 A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS use… Enterprise Linux after 0.8.0 Fix from $1,9502019-12-23 MEDIUM 5.5 CVE-2019-18391 A heap-based buffer overflow in the vrend_renderer_transfer_write_iov function in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS use… Enterprise Linux after 0.8.0 Fix from $1,6002019-12-23 CRITICAL 9.8 CVE-2019-19333 In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits… Enterprise Linux Patch available Fix from $2,3002019-12-06 CRITICAL 9.8 CVE-2019-19334 In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "iden… Enterprise Linux Patch available Fix from $2,3002019-12-06 HIGH 7.0 CVE-2019-9755 An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafte… Enterprise Linux Mitigation only Fix from $1,9502019-06-05 MEDIUM 5.5 CVE-2019-7664 In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf in… Enterprise Linux No fix yet Fix from $1,6002019-02-09 HIGH 8.8 CVE-2018-5805 A boundary error within the "quicktake_100_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.8 can be exploited to ca… Enterprise Linux Desktop 0.18.8+ Fix from $1,9502018-12-07 MEDIUM 6.5 CVE-2018-5800 An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploi… Enterprise Linux Desktop 0.18.7+ Fix from $1,6002018-12-07 HIGH 8.8 CVE-2018-14653 The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_… Gluster Storage after 4.1.4 Fix from $1,9502018-10-31 HIGH 7.8 CVE-2018-12379 When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a pote… Enterprise Linux Desktop 60.2.0 / 62.0+ Fix from $1,9502018-10-18 HIGH 7.7 CVE-2018-14632 An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An a… Openshift Container Platform after 3.7 Fix from $1,9502018-09-06 MEDIUM 5.5 CVE-2018-16542 In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during e… Enterprise Linux 9.24+ Fix from $1,6002018-09-05 HIGH 8.8 CVE-2018-10907 It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size… Virtualization Host 3.12.14 / 4.1.4+ Fix from $1,9502018-09-04 MEDIUM 6.5 CVE-2017-2633 An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshin… Enterprise Linux Desktop 1.7.2+ Fix from $1,6002018-07-27 HIGH 7.8 CVE-2018-5002 KEVEPSS 25% Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary … Enterprise Linux Desktop after 29.0.0.171 Fix from $1,9502018-07-09 HIGH 8.8 CVE-2018-5146EPSS 12% An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.… Enterprise Linux Desktop Mitigation only Fix from $1,9502018-06-11 CRITICAL 9.8 CVE-2018-11236EPSS 7% stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath functi… Virtualization Host after 2.27 Fix from $2,3002018-05-18 HIGH 7.8 CVE-2018-11237 An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the targ… Virtualization Host after 2.27 Fix from $1,9502018-05-18 MEDIUM 5.5 CVE-2018-10534 The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B… Enterprise Linux Desktop Mitigation only Fix from $1,6002018-04-29 HIGH 8.8 CVE-2016-5314 Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (a… Enterprise Linux after 4.0.6 Fix from $1,9502018-03-12 CRITICAL 9.8 CVE-2018-6485 An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier coul… Virtualization Host after 2.26 Fix from $2,3002018-02-01 CRITICAL 9.8 CVE-2017-14491EPSS 85% Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafte… Enterprise Linux Desktop after 2.77 Fix from $2,3002017-10-04