Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Debian Linux CRITICAL 9.8
CVE-2017-12424

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may l…

Fix: 4.5+
Fix from $2,300 2017-08-04
Ioquake3 CRITICAL 9.8
CVE-2017-11721

Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified o…

Fix: after 2017-07-31
Fix from $2,300 2017-08-03
Wn Ax1167gr Firmware MEDIUM 6.8
CVE-2017-2282

Buffer overflow in WN-AX1167GR firmware version 3.00 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.

Mitigation only
Fix from $1,600 2017-08-02
Ytnef MEDIUM 5.5
CVE-2017-12141

In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denia…

Patch available
Fix from $1,600 2017-08-02
Outlook HIGH 7.8
CVE-2017-8663EPSS 20%

Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a remote…

Patch available
Fix from $1,950 2017-08-01
Mad Libmad MEDIUM 6.5
CVE-2017-11552EPSS 7%

mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (m…

No fix yet
Fix from $1,600 2017-08-01
Libao MEDIUM 5.5
CVE-2017-11548

The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a c…

No fix yet
Fix from $1,600 2017-07-31
Libid3tag MEDIUM 5.5
CVE-2017-11551

The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file.

Mitigation only
Fix from $1,600 2017-07-31
Openexif MEDIUM 5.5
CVE-2017-11115

The ExifJpegHUFFTable::deriveTable function in ExifHuffmanTable.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-base…

No fix yet
Fix from $1,600 2017-07-31
Vorbis Tools MEDIUM 5.5
CVE-2017-11331

The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error)…

No fix yet
Fix from $1,600 2017-07-31
Debian Linux MEDIUM 5.5
CVE-2017-11732

A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/decompile.c in Ming 0.4.8, whic…

Mitigation only
Fix from $1,600 2017-07-29
Gpu Driver MEDIUM 6.5
CVE-2017-6260

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer helper function where an incorrect calculation of string length m…

Mitigation only
Fix from $1,600 2017-07-28
Audiocoder HIGH 7.8
CVE-2017-8870EPSS 14%

Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.

No fix yet
Fix from $1,950 2017-07-27
Antivirus HIGH 7.8
CVE-2016-10402EPSS 10%

Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative v…

Fix: after 8.3.36.59
Fix from $1,950 2017-07-27
Mediacoder HIGH 7.8
CVE-2017-8869EPSS 16%

Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.

No fix yet
Fix from $1,950 2017-07-27
Web Vulnerability Scanner MEDIUM 5.5
CVE-2017-11674

Reporter.exe in Acunetix 8 allows remote attackers to cause a denial of service (application crash) via a malformed PRE file, related to a "Read Acce…

No fix yet
Fix from $1,600 2017-07-27
Lame MEDIUM 5.5
CVE-2017-9412

The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and…

No fix yet
Fix from $1,600 2017-07-27
Libjpeg Turbo HIGH 8.8
CVE-2017-9614EPSS 8%

The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and a…

No fix yet
Fix from $1,950 2017-07-27
Ghostscript Ghostxps HIGH 7.8
CVE-2017-9618

The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (buffer ov…

No fix yet
Fix from $1,950 2017-07-26
Ghostscript Ghostxps HIGH 7.8
CVE-2017-9619

The xps_true_callback_glyph_name function in xps/xpsttf.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (…

No fix yet
Fix from $1,950 2017-07-26
Graphicsmagick CRITICAL 9.8
CVE-2017-11636

GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that have non-identical wid…

Mitigation only
Fix from $2,300 2017-07-26
Imagemagick MEDIUM 6.5
CVE-2017-11640

When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to an address access exception in the WritePTIFImage() function in coders/t…

Patch available
Fix from $1,600 2017-07-26
Graphicsmagick CRITICAL 9.8
CVE-2017-11643

GraphicsMagick 1.3.26 has a heap overflow in the WriteCMYKImage() function in coders/cmyk.c when processing multiple frames that have non-identical w…

Mitigation only
Fix from $2,300 2017-07-26
PHP HIGH 7.8
CVE-2017-11628

In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_pars…

Fix: after 5.6.30
Fix from $1,950 2017-07-25
Asr 5000 Series Software HIGH 8.6
CVE-2017-6612

A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow…

Mitigation only
Fix from $1,950 2017-07-25
Webex Event Center HIGH 8.8
CVE-2017-6753EPSS 6%

A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute ar…

Mitigation only
Fix from $1,950 2017-07-25
Ubuntu Linux HIGH 8.8
CVE-2015-1332

The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a …

Fix: after 1.9.0
Fix from $1,950 2017-07-25
Panda Antivirus Pro 2015 HIGH 7.8
CVE-2015-1438

Heap-based buffer overflow in Panda Security Kernel Memory Access Driver 1.0.0.13 allows attackers to execute arbitrary code with kernel privileges v…

No fix yet
Fix from $1,950 2017-07-25
Hangul Word Processor HIGH 7.8
CVE-2015-6585

hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" …

Mitigation only
Fix from $1,950 2017-07-25
Ubuntu Linux HIGH 7.8
CVE-2017-7980

Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary…

Patch available
Fix from $1,950 2017-07-25