Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
H2o HIGH 7.5
CVE-2017-10869

Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.

Fix: after 2.2.2
Fix from $1,950 2017-12-22
Qts CRITICAL 9.8
CVE-2017-17027

A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2017111…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qts CRITICAL 9.8
CVE-2017-17028

A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) …

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qts CRITICAL 9.8
CVE-2017-17029

A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2017…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qts CRITICAL 9.8
CVE-2017-17030

A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2017…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qts CRITICAL 9.8
CVE-2017-17031

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qts CRITICAL 9.8
CVE-2017-17032

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Qts CRITICAL 9.8
CVE-2017-17033

A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 2…

Fix: after 4.3.3.0378
Fix from $2,300 2017-12-21
Ubuntu Linux MEDIUM 5.5
CVE-2017-17811

In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that will cause a remote denial of service attack, related to a strcpy in …

No fix yet
Fix from $1,600 2017-12-21
Safari CRITICAL 9.8
CVE-2017-17821

WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows remote attackers to cause a denial of service (buff…

Mitigation only
Fix from $2,300 2017-12-21
Data Domain HIGH 7.5
CVE-2017-14385EPSS 5%

An issue was discovered in EMC Data Domain DD OS 5.7 family, versions prior to 5.7.5.6; EMC Data Domain DD OS 6.0 family, versions prior to 6.0.2.9; …

Fix: 5.7.5.6 / 6.0.2.9+
Fix from $1,950 2017-12-20
Levi Studio Hmi HIGH 8.6
CVE-2017-16717

A Heap-based Buffer Overflow issue was discovered in WECON LeviStudio HMI. The heap-based buffer overflow vulnerability has been identified, which ma…

Mitigation only
Fix from $1,950 2017-12-20
Ahb7008f8 H Firmware CRITICAL 9.8
CVE-2017-16725EPSS 9%

A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-base…

Mitigation only
Fix from $2,300 2017-12-20
Fusion HIGH 8.8
CVE-2017-4941

VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a vu…

Fix: 8.5.9 / 12.5.8+
Fix from $1,950 2017-12-20
Zoom HIGH 8.8
CVE-2017-15048EPSS 10%

Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitra…

Fix: 2.0.115900.1201+
Fix from $1,950 2017-12-19
Syncbreeze HIGH 7.5
CVE-2017-17088EPSS 7%

The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bound…

Fix: after 10.2.12
Fix from $1,950 2017-12-19
Openldap HIGH 7.5
CVE-2017-17740EPSS 7%

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buff…

Fix: 6.5.1 / 21.1.2+
Fix from $1,950 2017-12-18
Dir 850l Firmware HIGH 8.8
CVE-2017-3193EPSS 6%

Multiple D-Link devices including the DIR-850L firmware versions 1.14B07 and 2.07.B05 contain a stack-based buffer overflow vulnerability in the web …

Patch available
Fix from $1,950 2017-12-16
Edge CRITICAL 9.8
CVE-2017-3195EPSS 21%

Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulner…

Patch available
Fix from $2,300 2017-12-16
Rawether HIGH 7.8
CVE-2017-3196

PCAUSA Rawether framework does not properly validate BPF data, allowing a crafted malicious BPF program to perform operations on memory outside of it…

No fix yet
Fix from $1,950 2017-12-16
Panda Global Protection HIGH 7.5
CVE-2017-17683

Panda Global Protection 17.0.1 allows a system crash via a 0xb3702c44 \\.\PSMEMDriver DeviceIoControl request.

No fix yet
Fix from $1,950 2017-12-14
Panda Global Protection HIGH 7.5
CVE-2017-17684

Panda Global Protection 17.0.1 allows a system crash via a 0xb3702c04 \\.\PSMEMDriver DeviceIoControl request.

No fix yet
Fix from $1,950 2017-12-14
Asterisk MEDIUM 5.9
CVE-2017-17664EPSS 32%

A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk be…

Fix: 13.18.4 / 14.7.4+
Fix from $1,600 2017-12-13
Xen HIGH 7.8
CVE-2017-17563

An issue was discovered in Xen through 4.9.x allowing guest OS users to cause a denial of service (host OS crash) or gain host OS privileges by lever…

Fix: after 4.9.1
Fix from $1,950 2017-12-12
Office HIGH 7.8
CVE-2017-11935EPSS 19%

Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Exce…

Patch available
Fix from $1,950 2017-12-12
Edge HIGH 7.5
CVE-2017-11888EPSS 8%

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the cont…

Patch available
Fix from $1,950 2017-12-12
Chakracore HIGH 7.5
CVE-2017-11889EPSS 9%

ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the…

Fix: 1.7.5+
Fix from $1,950 2017-12-12
Edge HIGH 7.5
CVE-2017-11893EPSS 68%

ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code in the conte…

Fix: 1.7.5+
Fix from $1,950 2017-12-12
Chakracore HIGH 7.5
CVE-2017-11894EPSS 8%

ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and…

Fix: 1.7.5+
Fix from $1,950 2017-12-12
Chakracore HIGH 7.5
CVE-2017-11895EPSS 8%

ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and…

Fix: 1.7.5+
Fix from $1,950 2017-12-12