Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Sentinel Ldk Rte CRITICAL 9.8
CVE-2017-11496

Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote a…

Mitigation only
Fix from $2,300 2017-10-03
Sentinel Ldk Rte CRITICAL 9.8
CVE-2017-11497

Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote a…

Mitigation only
Fix from $2,300 2017-10-03
Sentinel Ldk Rte HIGH 7.5
CVE-2017-11498

Buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attacke…

Mitigation only
Fix from $1,950 2017-10-03
Imail Server CRITICAL 9.8
CVE-2017-12638

Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vec…

Fix: after 12.5.5
Fix from $2,300 2017-10-03
Imail Server CRITICAL 9.8
CVE-2017-12639

Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vec…

Fix: after 12.5.5
Fix from $2,300 2017-10-03
Gsview HIGH 7.8
CVE-2017-14945

Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, r…

No fix yet
Fix from $1,950 2017-09-30
Gsview HIGH 7.8
CVE-2017-14946

Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, r…

No fix yet
Fix from $1,950 2017-09-30
Gsview HIGH 7.8
CVE-2017-14947

Artifex GSView 6.0 Beta on Windows allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Rea…

No fix yet
Fix from $1,950 2017-09-30
Mcp Firmware HIGH 7.8
CVE-2017-13684

Unisys Libra 64xx and 84xx and FS601 class systems with MCP-FIRMWARE before 43.211 allow remote authenticated users to cause a denial of service (pro…

Fix: after 43.185
Fix from $1,950 2017-09-30
Exiv2 MEDIUM 5.5
CVE-2017-14866

There is a heap-based buffer overflow in the Exiv2::s2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service atta…

No fix yet
Fix from $1,600 2017-09-29
iOS CRITICAL 9.8
CVE-2017-12240 KEVEPSS 14%

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remot…

Fix: after 15.6
Fix from $2,300 2017-09-29
Exiv2 MEDIUM 5.5
CVE-2017-14858

There is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service atta…

No fix yet
Fix from $1,600 2017-09-29
Ubuntu Linux MEDIUM 5.5
CVE-2017-14859

An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentat…

No fix yet
Fix from $1,600 2017-09-29
Ubuntu Linux MEDIUM 5.5
CVE-2017-14862

An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fa…

No fix yet
Fix from $1,600 2017-09-29
Ubuntu Linux MEDIUM 5.5
CVE-2017-14864

An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and…

No fix yet
Fix from $1,600 2017-09-29
Exiv2 MEDIUM 5.5
CVE-2017-14865

There is a heap-based buffer overflow in the Exiv2::us2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service att…

Mitigation only
Fix from $1,600 2017-09-29
Bcm4355c0 Firmware CRITICAL 9.8
CVE-2017-11120EPSS 9%

On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an intern…

Fix: 11.0+
Fix from $2,300 2017-09-28
Bcm4355c0 Firmware CRITICAL 9.8
CVE-2017-11121

On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, properly crafted malicious over-the-air Fast Transition frames can potentially t…

Fix: 11.0+
Fix from $2,300 2017-09-28
Perl CRITICAL 9.8
CVE-2017-12814EPSS 7%

Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows…

Fix: after 5.24.2
Fix from $2,300 2017-09-28
Ffmpeg HIGH 8.8
CVE-2017-14767

The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allow…

Fix: after 3.3.3
Fix from $1,950 2017-09-27
Jerryscript HIGH 7.8
CVE-2017-14749

JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbi…

No fix yet
Fix from $1,950 2017-09-26
Clearscada HIGH 7.5
CVE-2017-9962

Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed reques…

Fix: after 2010
Fix from $1,950 2017-09-26
Libbpg HIGH 8.8
CVE-2017-14734

The build_msps function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (heap-based buffer overflow and application …

No fix yet
Fix from $1,950 2017-09-25
Systemd CRITICAL 9.8
CVE-2015-7510

Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.

Patch available
Fix from $2,300 2017-09-25
Binutils HIGH 7.8
CVE-2017-14729

The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, do not ensure a u…

Patch available
Fix from $1,950 2017-09-25
Labelprint HIGH 7.8
CVE-2017-14627EPSS 20%

Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION …

No fix yet
Fix from $1,950 2017-09-23
Logger HIGH 7.5
CVE-2017-14727

logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.

Patch available
Fix from $1,950 2017-09-23
Foxit Reader HIGH 7.8
CVE-2017-14694EPSS 7%

Foxit Reader 8.3.2.25013 and earlier and Foxit PhantomPDF 8.3.2.25013 and earlier, when running in single instance mode, allows attackers to execute …

Mitigation only
Fix from $1,950 2017-09-22
Stdu Viewer HIGH 7.8
CVE-2017-14688

STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to a "R…

Mitigation only
Fix from $1,950 2017-09-22
Stdu Viewer HIGH 7.8
CVE-2017-14689

STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Dat…

Mitigation only
Fix from $1,950 2017-09-22