Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Traffic Server CRITICAL 9.8
CVE-2015-3249EPSS 5%

The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds acces…

Mitigation only
Fix from $2,300 2017-10-30
Xen CRITICAL 9.1
CVE-2017-15597

An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page refer…

Fix: after 4.9.0
Fix from $2,300 2017-10-30
Binutils HIGH 7.8
CVE-2017-15996

elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a denial of service (excessive memory allocation) or possibly have unspeci…

Patch available
Fix from $1,950 2017-10-29
Debian Linux MEDIUM 5.5
CVE-2017-15953

bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE (.cue) file.

Patch available
Fix from $1,600 2017-10-28
Debian Linux MEDIUM 5.5
CVE-2017-15954

bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a resultant invalid free) and crash when processin…

Patch available
Fix from $1,600 2017-10-28
Binutils HIGH 7.5
CVE-2017-15938

dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, miscalculates DW_FORM_ref_addr die refs in th…

Patch available
Fix from $1,950 2017-10-27
Debian Linux HIGH 8.8
CVE-2017-13089EPSS 80%

The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the response is sent chunked in wget b…

Fix: after 1.19.1
Fix from $1,950 2017-10-27
Debian Linux HIGH 8.8
CVE-2017-13090EPSS 37%

The retr.c:fd_read_body() function is called when processing OK responses. When the response is sent chunked in wget before 1.19.2, the chunk parser …

Fix: after 1.19.1
Fix from $1,950 2017-10-27
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2017-6162

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, Websafe software version 12.0.0 to 12.1.2, 11.6.0 to 1…

Fix: after 11.5.4
Fix from $1,600 2017-10-27
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2017-6163

In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, PSM software version 12.0.0 to 12.1.2, 11.6.0 to 11.6.1, 11.4.0 to 11.5.4, when a virtual…

Fix: after 11.5.4
Fix from $1,600 2017-10-27
Chrome HIGH 8.8
CVE-2017-5112EPSS 5%

Heap buffer overflow in WebGL in Google Chrome prior to 61.0.3163.79 for Windows allowed a remote attacker to execute arbitrary code inside a sandbox…

Fix: 61.0.3163.79+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5114

Inappropriate use of partition alloc in PDFium in Google Chrome prior to 61.0.3163.79 for Linux, Windows, and Mac, and 61.0.3163.81 for Android, allo…

Fix: 61.0.3163.79 / 61.0.3163.81+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5122

Inappropriate use of table size handling in V8 in Google Chrome prior to 61.0.3163.100 for Windows allowed a remote attacker to trigger out-of-bounds…

Fix: 61.0.3163.100+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5052

An incorrect assumption about block structure in Blink in Google Chrome prior to 57.0.2987.133 for Mac, Windows, and Linux, and 57.0.2987.132 for And…

Fix: 57.0.2987.132 / 57.0.2987.133+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5064

Incorrect handling of DOM changes in Blink in Google Chrome prior to 58.0.3029.81 for Windows allowed a remote attacker to potentially exploit heap c…

Fix: 58.0.3029.81+
Fix from $1,950 2017-10-27
Webop HIGH 7.8
CVE-2017-12705

A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to trigger a heap-based buffer o…

Mitigation only
Fix from $1,950 2017-10-25
Wr940n Firmware HIGH 8.8
CVE-2017-13772EPSS 53%

Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary co…

No fix yet
Fix from $1,950 2017-10-23
Extremexos HIGH 7.5
CVE-2017-14328

Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot.

Mitigation only
Fix from $1,950 2017-10-23
Safari HIGH 8.8
CVE-2017-7117EPSS 10%

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected.…

Fix: after 12.6.2
Fix from $1,950 2017-10-23
Safari HIGH 8.8
CVE-2017-7120

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected.…

Fix: after 12.6.2
Fix from $1,950 2017-10-23
Iphone Os HIGH 7.8
CVE-2017-7127

An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. iCloud before 7.0 on Windows is affecte…

Fix: after 10.12.6
Fix from $1,950 2017-10-23
Iphone Os CRITICAL 9.8
CVE-2017-7128

An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS bef…

Fix: after 10.12.6
Fix from $2,300 2017-10-23
Iphone Os CRITICAL 9.8
CVE-2017-7129

An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS bef…

Fix: after 10.12.6
Fix from $2,300 2017-10-23
Iphone Os CRITICAL 9.8
CVE-2017-7130

An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS bef…

Fix: after 10.12.6
Fix from $2,300 2017-10-23
Xcode HIGH 7.8
CVE-2017-7134

An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to…

Fix: after 8.3.3
Fix from $1,950 2017-10-23
Xcode HIGH 7.8
CVE-2017-7135

An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to…

Fix: after 8.3.3
Fix from $1,950 2017-10-23
Xcode HIGH 7.8
CVE-2017-7136

An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to…

Fix: after 8.3.3
Fix from $1,950 2017-10-23
Xcode HIGH 7.8
CVE-2017-7137

An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to…

Fix: after 8.3.3
Fix from $1,950 2017-10-23
Safari HIGH 8.8
CVE-2017-7091

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected.…

Fix: after 12.6.2
Fix from $1,950 2017-10-23
Safari HIGH 8.8
CVE-2017-7092EPSS 5%

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected.…

Fix: after 12.6.2
Fix from $1,950 2017-10-23