Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Safari HIGH 8.8
CVE-2017-13795EPSS 6%

An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is aff…

Fix: 7.1 / 11.0.1+
Fix from $1,950 2017-11-13
Safari HIGH 8.8
CVE-2017-13796EPSS 6%

An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is aff…

Fix: 7.1 / 11.0.1+
Fix from $1,950 2017-11-13
Safari HIGH 8.8
CVE-2017-13797EPSS 5%

An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is aff…

Fix: 7.1 / 11.0.1+
Fix from $1,950 2017-11-13
Safari HIGH 8.8
CVE-2017-13798EPSS 6%

An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is aff…

Fix: 7.1 / 11.0.1+
Fix from $1,950 2017-11-13
Iphone Os HIGH 7.8
CVE-2017-13799

An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watch…

Fix: 4.1 / 10.13.1+
Fix from $1,950 2017-11-13
Mac Os X HIGH 7.8
CVE-2017-13800

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "APFS" component. It allows attackers to …

Fix: after 10.13.0
Fix from $1,950 2017-11-13
Safari HIGH 8.8
CVE-2017-13802EPSS 6%

An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is aff…

Fix: 7.1 / 11.0.1+
Fix from $1,950 2017-11-13
Swftools HIGH 7.8
CVE-2017-16796

In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows remote attackers to cause a den…

Mitigation only
Fix from $1,950 2017-11-12
Swftools HIGH 7.8
CVE-2017-16793

The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote attackers to cause a denial of …

Mitigation only
Fix from $1,950 2017-11-12
Ip Office Contact Center HIGH 8.8
CVE-2017-12969EPSS 10%

Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a de…

No fix yet
Fix from $1,950 2017-11-10
Ip Office CRITICAL 9.6
CVE-2017-11309EPSS 9%

Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.

Fix: 10.1.1+
Fix from $2,300 2017-11-10
Debian Linux HIGH 8.8
CVE-2017-16669

coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or poss…

Patch available
Fix from $1,950 2017-11-09
Asterisk HIGH 8.8
CVE-2017-16671

A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13…

Fix: 13.18.1 / 14.7.1+
Fix from $1,950 2017-11-09
Inpage HIGH 7.8
CVE-2017-12824

Special crafted InPage document leads to arbitrary code execution in InPage reader.

No fix yet
Fix from $1,950 2017-11-08
Webaccess MEDIUM 6.3
CVE-2017-14016EPSS 16%

A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of…

Fix: 8.2_20170817+
Fix from $1,600 2017-11-06
Ubuntu Linux HIGH 8.8
CVE-2017-16546

The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote …

Patch available
Fix from $1,950 2017-11-05
Linux Kernel MEDIUM 6.8
CVE-2017-16534

The cdc_parse_cdc_header function in drivers/usb/core/message.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (ou…

Fix: 4.4.92 / 4.9.55+
Fix from $1,600 2017-11-04
Linux Kernel HIGH 7.8
CVE-2017-16526

drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection fault and system crash) or p…

Fix: 3.2.97 / 3.16.52+
Fix from $1,950 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16531

drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or …

Fix: 3.2.95 / 3.16.75+
Fix from $1,600 2017-11-04
Ws Ftp HIGH 7.8
CVE-2017-16513

Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations field, aka WSCLT-1729.

Fix: 12.6.0.3+
Fix from $1,950 2017-11-03
Chakracore CRITICAL 9.8
CVE-2017-11767EPSS 10%

ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects i…

Mitigation only
Fix from $2,300 2017-11-02
Wireless Lan Controller Software MEDIUM 6.3
CVE-2017-12278

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Wireless LAN Controllers could allow an authenticated, remote att…

Mitigation only
Fix from $1,600 2017-11-02
Wireless Lan Controller Software HIGH 7.5
CVE-2017-12280

A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) Discovery Request parsing functionality of Cisco Wireless LAN Cont…

Mitigation only
Fix from $1,950 2017-11-02
Wireless Lan Controller Software MEDIUM 6.1
CVE-2017-12282

A vulnerability in the Access Network Query Protocol (ANQP) ingress frame processing functionality of Cisco Wireless LAN Controllers could allow an u…

Mitigation only
Fix from $1,600 2017-11-02
Aironet 3800 Firmware MEDIUM 6.1
CVE-2017-12283

A vulnerability in the handling of 802.11w Protected Management Frames (PAF) by Cisco Aironet 3800 Series Access Points could allow an unauthenticate…

Mitigation only
Fix from $1,600 2017-11-02
Easy Postcard 2016 HIGH 7.8
CVE-2017-10870

Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for …

Patch available
Fix from $1,950 2017-11-02
Radare2 HIGH 7.8
CVE-2017-16357

In radare 2.0.1, a memory corruption vulnerability exists in store_versioninfo_gnu_verdef() and store_versioninfo_gnu_verneed() in libr/bin/format/el…

Patch available
Fix from $1,950 2017-11-01
Debian Linux HIGH 8.8
CVE-2017-16352EPSS 15%

GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the Descri…

No fix yet
Fix from $1,950 2017-11-01
Debian Linux CRITICAL 9.1
CVE-2017-1000257EPSS 6%

An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl woul…

Fix: after 7.56.0
Fix from $2,300 2017-10-31
Syncbreeze HIGH 7.8
CVE-2017-15950EPSS 6%

Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is tri…

No fix yet
Fix from $1,950 2017-10-31