Total
6166 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-14736 | 1 Pbc Project | 1 Pbc | 2018-09-26 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A buffer over-read can occur in pbc_wmessage_string in wmessage.c for PTYPE_ENUM. | |||||
CVE-2018-1999015 | 1 Ffmpeg | 1 Ffmpeg | 2018-09-20 | 4.3 MEDIUM | 6.5 MEDIUM |
FFmpeg before commit 5aba5b89d0b1d73164d3b81764828bb8b20ff32a contains an out of array read vulnerability in ASF_F format demuxer that can result in heap memory reading. This attack appear to be exploitable via specially crafted ASF file that has to provided as input. This vulnerability appears to have been fixed in 5aba5b89d0b1d73164d3b81764828bb8b20ff32a and later. | |||||
CVE-2018-1999014 | 1 Ffmpeg | 1 Ffmpeg | 2018-09-19 | 4.3 MEDIUM | 6.5 MEDIUM |
FFmpeg before commit bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 contains an out of array access vulnerability in MXF format demuxer that can result in DoS. This attack appear to be exploitable via specially crafted MXF file which has to be provided as input. This vulnerability appears to have been fixed in bab0716c7f4793ec42e05a5aa7e80d82a0dd4e75 and later. | |||||
CVE-2018-14545 | 1 Axiosys | 1 Bento4 | 2018-09-19 | 4.3 MEDIUM | 5.5 MEDIUM |
There exists one invalid memory read bug in AP4_SampleDescription::GetType() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts. | |||||
CVE-2018-14544 | 1 Axiosys | 1 Bento4 | 2018-09-19 | 4.3 MEDIUM | 5.5 MEDIUM |
There exists one invalid memory read bug in AP4_SampleDescription::GetFormat() in Ap4SampleDescription.h in Bento4 1.5.1-624, which can allow attackers to cause a denial-of-service via a crafted mp4 file. This vulnerability can be triggered by the executable mp42ts. | |||||
CVE-2018-5008 | 6 Adobe, Apple, Google and 3 more | 11 Flash Player, Flash Player Desktop Runtime, Mac Os X and 8 more | 2018-09-17 | 5.0 MEDIUM | 7.5 HIGH |
Adobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |||||
CVE-2018-14444 | 1 Libdxfrw Project | 1 Libdxfrw | 2018-09-17 | 5.0 MEDIUM | 7.5 HIGH |
libdxfrw 0.6.3 has an Integer Overflow in dwgCompressor::decompress18 in dwgutil.cpp, leading to an out-of-bounds read and application crash. | |||||
CVE-2018-14401 | 1 Axml Parser Project | 1 Axml Parser | 2018-09-17 | 5.0 MEDIUM | 7.5 HIGH |
CopyData in AxmlParser.c in AXML Parser through 2018-01-04 has an out-of-bounds read. | |||||
CVE-2018-14447 | 2 Debian, Libconfuse Project | 2 Debian Linux, Libconfuse | 2018-09-14 | 6.8 MEDIUM | 8.8 HIGH |
trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read. | |||||
CVE-2018-14454 | 1 Linuxsampler | 1 Libgig | 2018-09-11 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in libgig 4.1.0. There is an out-of-bounds read in the function RIFF::Chunk::Read in RIFF.cpp. | |||||
CVE-2018-14452 | 1 Linuxsampler | 1 Libgig | 2018-09-11 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in libgig 4.1.0. There is an out-of-bounds read in the "always assign the sample of the first dimension region of this region" feature of the function gig::Region::UpdateChunks in gig.cpp. | |||||
CVE-2018-14450 | 1 Linuxsampler | 1 Libgig | 2018-09-11 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in libgig 4.1.0. There is an out-of-bounds read in the "update dimension region's chunks" feature of the function gig::Region::UpdateChunks in gig.cpp. | |||||
CVE-2018-14449 | 1 Linuxsampler | 1 Libgig | 2018-09-11 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in libgig 4.1.0. There is an out of bounds read in gig::File::UpdateChunks in gig.cpp. | |||||
CVE-2018-14033 | 1 Hdfgroup | 1 Hdf5 | 2018-09-11 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5O_layout_decode in H5Olayout.c, related to HDmemcpy. | |||||
CVE-2018-14031 | 1 Hdfgroup | 1 Hdf5 | 2018-09-11 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5T_copy in H5T.c. | |||||
CVE-2018-14034 | 1 Hdfgroup | 1 Hdf5 | 2018-09-11 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out of bounds read in the function H5O_pline_reset in H5Opline.c. | |||||
CVE-2018-14035 | 1 Hdfgroup | 1 Hdf5 | 2018-09-11 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in the HDF HDF5 1.8.20 library. There is a heap-based buffer over-read in the function H5VM_memcpyvv in H5VM.c. | |||||
CVE-2018-6969 | 1 Vmware | 1 Tools | 2018-09-11 | 4.4 MEDIUM | 7.0 HIGH |
VMware Tools (10.x and prior before 10.3.0) contains an out-of-bounds read vulnerability in HGFS. Successful exploitation of this issue may lead to information disclosure or may allow attackers to escalate their privileges on the guest VMs. In order to be able to exploit this issue, file sharing must be enabled. | |||||
CVE-2017-17316 | 1 Huawei | 12 Dp300, Dp300 Firmware, Rp200 and 9 more | 2018-09-11 | 5.0 MEDIUM | 5.3 MEDIUM |
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; TE50 V500R002C00; V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00 have an out-of-bounds read vulnerability. An unauthenticated, remote attacker has to control the peer device and craft the Signalling Connection Control Part (SCCP) messages to the target devices. Due to insufficient input validation of some values in the messages, successful exploit will cause out-of-bounds read and some services abnormal. | |||||
CVE-2018-13875 | 1 Hdfgroup | 1 Hdf5 | 2018-09-07 | 6.8 MEDIUM | 7.8 HIGH |
An issue was discovered in the HDF HDF5 1.8.20 library. There is an out-of-bounds read in the function H5VM_memcpyvv in H5VM.c. |