Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Debian Linux HIGH 7.8
CVE-2018-5996

Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruption…

Fix: 18.00 / 18.0+
Fix from $1,950 2018-01-31
S9300 Firmware HIGH 7.5
CVE-2014-4705

Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S6300, and S6700 series switch…

Mitigation only
Fix from $1,950 2018-01-30
Wps Office MEDIUM 6.5
CVE-2018-6390

The WStr::assign function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 does not validate the size of the source memory block before …

No fix yet
Fix from $1,600 2018-01-29
Ubuntu Linux MEDIUM 6.5
CVE-2018-6381

In ZZIPlib 0.13.67, 0.13.66, 0.13.65, 0.13.64, 0.13.63, 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57 and 0.13.56 there is a segmentation faul…

No fix yet
Fix from $1,600 2018-01-29
Debian Linux HIGH 7.5
CVE-2017-12375EPSS 6%

The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denia…

Fix: after 0.99.2
Fix from $1,950 2018-01-26
Debian Linux HIGH 7.8
CVE-2017-12376EPSS 7%

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of…

Fix: after 0.99.2
Fix from $1,950 2018-01-26
Debian Linux CRITICAL 9.8
CVE-2017-12379EPSS 13%

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of…

Fix: after 0.99.2
Fix from $2,300 2018-01-26
Debian Linux MEDIUM 5.5
CVE-2018-6192

In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violatio…

No fix yet
Fix from $1,600 2018-01-24
Dupscout CRITICAL 9.8
CVE-2017-13696EPSS 78%

A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise…

No fix yet
Fix from $2,300 2018-01-24
Sysgauge HIGH 8.1
CVE-2018-5359EPSS 9%

The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system-level access because of a Bu…

No fix yet
Fix from $1,950 2018-01-23
Android HIGH 7.0
CVE-2016-5345

Buffer overflow in the Qualcomm radio driver in Android before 2017-01-05 on Android One devices allows local users to gain privileges via a crafted …

Patch available
Fix from $1,950 2018-01-23
Mupdf HIGH 7.8
CVE-2017-17858

Heap-based buffer overflow in the ensure_solid_xref function in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 allows a remote attacker to potentially execut…

Patch available
Fix from $1,950 2018-01-22
Nfsaxe CRITICAL 9.8
CVE-2017-18047EPSS 20%

Buffer Overflow in the FTP client in LabF nfsAxe 3.7 allows remote FTP servers to execute arbitrary code via a long reply.

No fix yet
Fix from $2,300 2018-01-22
H640x Firmware CRITICAL 9.8
CVE-2017-18046EPSS 5%

Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code…

No fix yet
Fix from $2,300 2018-01-21
Libav HIGH 8.8
CVE-2018-5766

In Libav through 12.2, there is an invalid memcpy in the av_packet_ref function of libavcodec/avpacket.c. Remote attackers could leverage this vulner…

Fix: after 12.2
Fix from $1,950 2018-01-18
Thinkfree Office Neo CRITICAL 9.8
CVE-2018-5195

Hancom NEO versions 9.6.1.5183 and earlier have a buffer Overflow vulnerability that leads remote attackers to execute arbitrary commands when perfor…

Fix: after 9.6.1.5183
Fix from $2,300 2018-01-17
Android HIGH 7.8
CVE-2017-11072

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while calculating CRC for GPT header …

Patch available
Fix from $1,950 2018-01-16
Linux Kernel HIGH 8.1
CVE-2017-15126

A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of fork failure when deal…

Fix: 4.13.6+
Fix from $1,950 2018-01-14
Linux Kernel MEDIUM 5.5
CVE-2017-15128

A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a deni…

Fix: after 4.13.11
Fix from $1,600 2018-01-14
Libav HIGH 8.8
CVE-2018-5684

In Libav through 12.2, there is an invalid memcpy call in the ff_mov_read_stsd_entries function of libavformat/mov.c. Remote attackers could leverage…

Fix: after 12.2
Fix from $1,950 2018-01-14
Android HIGH 7.8
CVE-2017-13225

In libMtkOmxVdec.so there is a possible heap buffer overflow. This could lead to a remote elevation of privilege enabling code execution as a privile…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.5
CVE-2017-13197

In the ihevcd_parse_slice.c function, slave threads are not joined if there is an error. This could lead to a remote denial of service of a critical …

Patch available
Fix from $1,950 2018-01-12
Android CRITICAL 9.8
CVE-2017-13208EPSS 9%

In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing bounds check on the DHCP response. This could lea…

Patch available
Fix from $2,300 2018-01-12
Android CRITICAL 9.8
CVE-2017-13177

In several functions of libhevc, NEON registers are not preserved. This could lead to remote code execution as a privileged process with no additiona…

No fix yet
Fix from $2,300 2018-01-12
Levistudio Hmi Editor Firmware HIGH 7.8
CVE-2017-16737

An issue was discovered in WECON Technology LEVI Studio HMI Editor v1.8.29 and prior. A specially-crafted malicious file may be able to cause a heap-…

Fix: after 1.8.29
Fix from $1,950 2018-01-12
Levistudio Hmi Editor Firmware HIGH 7.8
CVE-2017-16739

An issue was discovered in WECON Technology LEVI Studio HMI Editor v1.8.29 and prior. Specially-crafted malicious files may be able to cause stack-ba…

Fix: after 1.8.29
Fix from $1,950 2018-01-12
Wireshark MEDIUM 6.5
CVE-2018-5334

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signat…

Fix: after 2.4.3
Fix from $1,600 2018-01-11
Wireshark MEDIUM 6.5
CVE-2018-5335

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. This was addressed in epan/dissectors/packet-wcp.c by validating the …

Fix: after 2.4.3
Fix from $1,600 2018-01-11
Wireshark HIGH 7.5
CVE-2018-5336

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addressed in epan/tvbparse.c by l…

Fix: after 2.4.3
Fix from $1,950 2018-01-11
Windriver HIGH 7.8
CVE-2018-5189

Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain system privileges by flipping pool…

Fix: 12.6.0+
Fix from $1,950 2018-01-11