Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Chrome Os CRITICAL 9.8
CVE-2016-5179

Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot.

Fix: 53.0.2785.144+
Fix from $2,300 2018-03-07
Ubuntu Linux HIGH 7.8
CVE-2018-1000100

GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap c…

Fix: after 0.7.1
Fix from $1,950 2018-03-06
Ubuntu Linux MEDIUM 6.5
CVE-2018-7725

An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability c…

No fix yet
Fix from $1,600 2018-03-06
Ubuntu Linux MEDIUM 6.5
CVE-2018-7726

An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_directory function of zip.c. Attackers could leverag…

No fix yet
Fix from $1,600 2018-03-06
Dp300 Firmware MEDIUM 5.5
CVE-2017-17136

PEM module of Huawei DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; …

Mitigation only
Fix from $1,600 2018-03-05
Dp300 Firmware MEDIUM 5.3
CVE-2017-17142

SIP module in Huawei DP300 V500R002C00; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC500; V500R002C00SPC…

Mitigation only
Fix from $1,600 2018-03-05
Dp300 Firmware MEDIUM 5.3
CVE-2017-17143

SIP module in Huawei DP300 V500R002C00; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC500; V500R002C00SPC…

Mitigation only
Fix from $1,600 2018-03-05
Dp300 Firmware MEDIUM 5.3
CVE-2017-17144

Backup feature of SIP module in Huawei DP300 V500R002C00; V500R002C00SPC100; V500R002C00SPC200; V500R002C00SPC300; V500R002C00SPC400; V500R002C00SPC5…

Mitigation only
Fix from $1,600 2018-03-05
Oncell G3110 Hspa Firmware HIGH 7.5
CVE-2018-5453

An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An…

Fix: after 1.4
Fix from $1,950 2018-03-05
Openjpeg CRITICAL 9.8
CVE-2018-7648

An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when…

Patch available
Fix from $2,300 2018-03-02
Enterprise Linux HIGH 7.5
CVE-2017-15134

A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain L…

Fix: 1.3.6.13 / 1.3.7.9+
Fix from $1,950 2018-03-01
Cimg HIGH 7.8
CVE-2018-7587

An issue was discovered in CImg v.220. DoS occurs when loading a crafted bmp image that triggers an allocation failure in load_bmp in CImg.h.

No fix yet
Fix from $1,950 2018-03-01
PHP CRITICAL 9.8
CVE-2018-7584EPSS 87%

In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an …

Fix: 7.0.28+
Fix from $2,300 2018-03-01
Ftpshell Client CRITICAL 9.8
CVE-2018-7573EPSS 69%

An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with the FTP 220 response code to c…

No fix yet
Fix from $2,300 2018-03-01
Debian Linux CRITICAL 9.8
CVE-2018-7552

There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead t…

No fix yet
Fix from $2,300 2018-02-28
Ubuntu Linux CRITICAL 9.8
CVE-2014-10071

In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.

Fix: 5.0.7+
Fix from $2,300 2018-02-27
Zsh CRITICAL 9.8
CVE-2014-10072

In utils.c in zsh before 5.0.6, there is a buffer overflow when scanning very long directory paths for symbolic links.

Fix: 5.0.6+
Fix from $2,300 2018-02-27
Ubuntu Linux CRITICAL 9.8
CVE-2017-18206

In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.

Fix: 5.4+
Fix from $2,300 2018-02-27
Disksavvy CRITICAL 9.8
CVE-2018-6481EPSS 21%

A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sendin…

No fix yet
Fix from $2,300 2018-02-27
Unixodbc CRITICAL 9.8
CVE-2018-7485

The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to caus…

Patch available
Fix from $2,300 2018-02-26
Imagemagick MEDIUM 6.5
CVE-2018-7470

An issue was discovered in ImageMagick 7.0.7-22 Q16. The IsWEBPImageLossless function in coders/webp.c allows attackers to cause a denial of service …

No fix yet
Fix from $1,600 2018-02-25
Android HIGH 7.8
CVE-2017-14884

In all Qualcomm products with Android releases from CAF using the Linux kernel, due to lack of bounds checking on the variable "data_len" from the fu…

Mitigation only
Fix from $1,950 2018-02-23
Android HIGH 7.8
CVE-2017-17767

In all Qualcomm products with Android releases from CAF using the Linux kernel, the IL client may free a buffer OMX Video Encoder Component and then …

Mitigation only
Fix from $1,950 2018-02-23
Mp4v2 HIGH 8.8
CVE-2018-7339

The MP4Atom class in mp4atom.cpp in MP4v2 through 2.0.0 mishandles Entry Number validation for the MP4 Table Property, which allows remote attackers …

Fix: after 2.0.0
Fix from $1,950 2018-02-23
Unixodbc CRITICAL 9.8
CVE-2018-7409

In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.

Fix: 2.3.5+
Fix from $2,300 2018-02-22
Linux Kernel MEDIUM 5.5
CVE-2017-18193

fs/f2fs/extent_cache.c in the Linux kernel before 4.13 mishandles extent trees, which allows local users to cause a denial of service (BUG) via an ap…

Fix: 4.13+
Fix from $1,600 2018-02-22
Debian Linux HIGH 7.5
CVE-2018-7284EPSS 58%

A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.1…

Fix: after 15.2.1
Fix from $1,950 2018-02-22
Prime Collaboration Provisioning HIGH 7.5
CVE-2018-0204

A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a deni…

Mitigation only
Fix from $1,950 2018-02-22
Debian Linux MEDIUM 5.9
CVE-2015-5314

The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough fo…

Fix: 2.6+
Fix from $1,600 2018-02-21
Debian Linux MEDIUM 5.9
CVE-2015-5315

The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for …

Fix: 2.6+
Fix from $1,600 2018-02-21