Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Android HIGH 7.8
CVE-2017-11059

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, setting the HMAC key by different thr…

Mitigation only
Fix from $1,950 2017-10-10
Android HIGH 7.8
CVE-2017-11067

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the Athdiag procfs entry does not hav…

Mitigation only
Fix from $1,950 2017-10-10
Fedora MEDIUM 6.5
CVE-2014-9092

libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.

Fix: after 1.2.90
Fix from $1,600 2017-10-10
Syncbreeze CRITICAL 9.8
CVE-2017-14980EPSS 22%

Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.

No fix yet
Fix from $2,300 2017-10-10
Debian Linux HIGH 7.8
CVE-2017-13723

In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing c…

Fix: after 1.19.3
Fix from $1,950 2017-10-10
Gnu Mpfr CRITICAL 9.8
CVE-2014-9474

Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have unspecified impact via vectors r…

Fix: after 3.1.2
Fix from $2,300 2017-10-10
Chrome MEDIUM 5.5
CVE-2015-1206

Heap-based buffer overflow in Google Chrome before M40 allows remote attackers to cause a denial of service (unpaged memory write and process crash) …

Fix: after 41.0.2251.0
Fix from $1,600 2017-10-06
Libcurl HIGH 7.5
CVE-2017-1000254EPSS 8%

libcurl may read outside of a heap allocated buffer when doing FTP. When libcurl connects to an FTP server and successfully logs in (anonymous or not…

Patch available
Fix from $1,950 2017-10-06
Lame MEDIUM 5.5
CVE-2017-15046

LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vul…

No fix yet
Fix from $1,600 2017-10-06
Redis CRITICAL 9.8
CVE-2017-15047

The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application c…

Patch available
Fix from $2,300 2017-10-06
Officescan HIGH 7.0
CVE-2017-14088

Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and esc…

Patch available
Fix from $1,950 2017-10-06
Officescan CRITICAL 9.8
CVE-2017-14089EPSS 10%

An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the Offic…

Patch available
Fix from $2,300 2017-10-06
Intelligent Platforms Proficy Hmi\/scada Cimplicity MEDIUM 6.8
CVE-2017-12732

A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet len…

Fix: after 9.0
Fix from $1,600 2017-10-05
Photoline HIGH 7.8
CVE-2017-12106

A memory corruption vulnerability exists in the .TGA parsing functionality of Computerinsel Photoline 20.02. A specially crafted .TGA file can cause …

No fix yet
Fix from $1,950 2017-10-05
Photoline HIGH 7.8
CVE-2017-2880

An memory corruption vulnerability exists in the .GIF parsing functionality of Computerinsel Photoline 20.02. A specially crafted .GIF file can cause…

No fix yet
Fix from $1,950 2017-10-05
Photoline HIGH 7.8
CVE-2017-2920

An memory corruption vulnerability exists in the .SVG parsing functionality of Computerinsel Photoline 20.02. A specially crafted .SVG file can cause…

Patch available
Fix from $1,950 2017-10-05
Virtual Wide Area Application Services MEDIUM 5.3
CVE-2017-12267

A vulnerability in the Independent Computing Architecture (ICA) accelerator feature for the Cisco Wide Area Application Services (WAAS) could allow a…

Mitigation only
Fix from $1,600 2017-10-05
Ios Xr HIGH 7.5
CVE-2017-12270

A vulnerability in the gRPC code of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an unauthenticat…

Mitigation only
Fix from $1,950 2017-10-05
Pyrobatchftp HIGH 7.5
CVE-2017-15035EPSS 6%

EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).

Fix: after 3.17
Fix from $1,950 2017-10-05
Curl MEDIUM 6.5
CVE-2017-1000101

curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfer…

Mitigation only
Fix from $1,600 2017-10-05
HTTP Server HIGH 7.5
CVE-2017-1000118

Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service

Fix: after 10.0.5
Fix from $1,950 2017-10-05
Enterprise Linux HIGH 7.8
CVE-2017-1000253 KEVEPSS 11%

Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committ…

Fix: 3.2.70 / 3.4.109+
Fix from $1,950 2017-10-05
Qt HIGH 7.5
CVE-2017-15011

The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause …

Mitigation only
Fix from $1,950 2017-10-04
Sentinel Ldk Rte Firmware HIGH 7.5
CVE-2017-12818

Stack overflow in custom XML-parser in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to re…

Fix: after 7.50
Fix from $1,950 2017-10-04
Sentinel Ldk Rte Firmware HIGH 7.5
CVE-2017-12820

Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version…

Fix: after 7.50
Fix from $1,950 2017-10-04
Sentinel Ldk Rte Firmware CRITICAL 9.8
CVE-2017-12821

Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 might cause remote code execu…

Fix: after 7.50
Fix from $2,300 2017-10-04
Android HIGH 7.8
CVE-2017-0809

A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7…

Patch available
Fix from $1,950 2017-10-04
Android HIGH 7.8
CVE-2017-0810

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Andr…

Patch available
Fix from $1,950 2017-10-04
Ubuntu Linux CRITICAL 9.8
CVE-2017-14492EPSS 93%

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafte…

Fix: after 2.77
Fix from $2,300 2017-10-03
Ubuntu Linux CRITICAL 9.8
CVE-2017-14493EPSS 84%

Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a craft…

Fix: after 2.77
Fix from $2,300 2017-10-03