Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Asx To Mp3 Converter HIGH 7.8
CVE-2017-15221EPSS 5%

ASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324.

No fix yet
Fix from $1,950 2017-10-16
Debian Linux MEDIUM 5.5
CVE-2017-15370

There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of…

No fix yet
Fix from $1,600 2017-10-16
Debian Linux MEDIUM 5.5
CVE-2017-15372

There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will le…

No fix yet
Fix from $1,600 2017-10-16
Office HIGH 7.8
CVE-2017-11825EPSS 22%

Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in th…

Patch available
Fix from $1,950 2017-10-13
Office Compatibility Pack HIGH 7.8
CVE-2017-11826 KEVEPSS 81%

Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer…

Patch available
Fix from $1,950 2017-10-13
Windows 10 MEDIUM 5.5
CVE-2017-8703

The Microsoft Windows Subsystem for Linux on Microsoft Windows 10 1703 allows a denial of service vulnerability when it improperly handles objects in…

Patch available
Fix from $1,600 2017-10-13
Windows 10 HIGH 7.8
CVE-2017-8717EPSS 24%

The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 1…

Patch available
Fix from $1,950 2017-10-13
Windows 10 HIGH 7.8
CVE-2017-8718EPSS 23%

The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 1…

Patch available
Fix from $1,950 2017-10-13
Windows 10 HIGH 7.5
CVE-2017-8727EPSS 8%

Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, a…

Patch available
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11796EPSS 9%

ChakraCore and Microsoft Edge in Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scri…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Edge HIGH 7.5
CVE-2017-11798EPSS 9%

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of…

Patch available
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11799EPSS 64%

ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Edge HIGH 7.5
CVE-2017-11800EPSS 9%

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the c…

Patch available
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11802EPSS 69%

ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11804EPSS 9%

ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in…

Patch available
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11805EPSS 9%

ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to ho…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11806EPSS 9%

ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to ho…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11807EPSS 9%

ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to ho…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11808EPSS 9%

ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11809EPSS 68%

ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Edge HIGH 7.5
CVE-2017-11811EPSS 65%

ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in…

Fix: 1.7.3+
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11812EPSS 47%

ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the c…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11821EPSS 9%

ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to ho…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Outlook HIGH 7.8
CVE-2017-11774 KEVEPSS 60%

Microsoft Outlook 2010 SP2, Outlook 2013 SP1 and RT SP1, and Outlook 2016 allow an attacker to execute arbitrary commands, due to how Microsoft Offic…

Patch available
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11792EPSS 9%

ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allow an attacker to execute arbitrary code in the context of the current user, due to how…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Ubuntu Linux HIGH 8.8
CVE-2017-15281

ReadPSDImage in coders/psd.c in ImageMagick 7.0.7-6 allows remote attackers to cause a denial of service (application crash) or possibly have unspeci…

Patch available
Fix from $1,950 2017-10-12
Loadrunner CRITICAL 9.8
CVE-2017-5789EPSS 18%

HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified …

Fix: after 12.53
Fix from $2,300 2017-10-11
Irfanview HIGH 7.8
CVE-2017-15254

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact v…

Mitigation only
Fix from $1,950 2017-10-11
Pdf HIGH 7.8
CVE-2017-15255

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact v…

Mitigation only
Fix from $1,950 2017-10-11
Pdf HIGH 7.8
CVE-2017-15256

IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact v…

Mitigation only
Fix from $1,950 2017-10-11