Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Irfanview HIGH 7.8
CVE-2017-10730

IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mo…

Mitigation only
Fix from $1,950 2017-07-05
Irfanview HIGH 7.8
CVE-2017-10731

IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mo…

Mitigation only
Fix from $1,950 2017-07-05
Irfanview HIGH 7.8
CVE-2017-10732

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, …

Mitigation only
Fix from $1,950 2017-07-05
Irfanview HIGH 7.8
CVE-2017-10733

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, …

Mitigation only
Fix from $1,950 2017-07-05
Irfanview HIGH 7.8
CVE-2017-10734

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, …

Mitigation only
Fix from $1,950 2017-07-05
Irfanview HIGH 7.8
CVE-2017-10735

IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, …

Mitigation only
Fix from $1,950 2017-07-05
Xnview HIGH 7.8
CVE-2017-10736

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a…

Mitigation only
Fix from $1,950 2017-07-05
Xnview HIGH 7.8
CVE-2017-10737

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a…

Mitigation only
Fix from $1,950 2017-07-05
Xnview HIGH 7.8
CVE-2017-10738

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a…

Mitigation only
Fix from $1,950 2017-07-05
Xnview HIGH 7.8
CVE-2017-10739

XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a…

Mitigation only
Fix from $1,950 2017-07-05
Radare2 HIGH 7.8
CVE-2017-10929

The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow …

Patch available
Fix from $1,950 2017-07-05
Xen CRITICAL 10.0
CVE-2017-10920

The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unma…

Fix: after 4.8.1
Fix from $2,300 2017-07-05
Xen CRITICAL 10.0
CVE-2017-10921

The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows…

Fix: after 4.8.1
Fix from $2,300 2017-07-05
Graphicsmagick MEDIUM 5.5
CVE-2017-10794

When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a buffer overflow occ…

Patch available
Fix from $1,600 2017-07-02
Aeroadmin HIGH 7.5
CVE-2017-8893

AeroAdmin 4.1 uses a function to copy data between two pointers where the size of the data copied is taken directly from a network packet. This can c…

No fix yet
Fix from $1,950 2017-07-02
Antivirus Engine MEDIUM 6.2
CVE-2017-10706

When Antiy Antivirus Engine before 5.0.0.05171547 scans a special ZIP archive, it crashes with a stack-based buffer overflow because a fixed path len…

No fix yet
Fix from $1,600 2017-07-02
Ncurses CRITICAL 9.8
CVE-2017-10684

In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution atta…

Mitigation only
Fix from $2,300 2017-06-29
Informix Dynamic Server MEDIUM 6.5
CVE-2017-1310

IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the serv…

Patch available
Fix from $1,600 2017-06-29
Windows Defender HIGH 7.8
CVE-2017-8558EPSS 44%

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2…

No fix yet
Fix from $1,950 2017-06-29
Libdwarf MEDIUM 6.5
CVE-2017-9998

The _dwarf_decode_s_leb128_chk function in dwarf_leb.c in libdwarf through 2017-06-28 allows remote attackers to cause a denial of service (Segmentat…

Fix: after 2017-06-28
Fix from $1,600 2017-06-28
Libav HIGH 7.5
CVE-2017-9987

There is a heap-based buffer overflow in the function hpel_motion in mpegvideo_motion.c in libav 12.1. A crafted input can lead to a remote denial of…

No fix yet
Fix from $1,950 2017-06-28
Ffmpeg HIGH 8.8
CVE-2017-9990

Stack-based buffer overflow in the color_string_to_rgba function in libavcodec/xpmdec.c in FFmpeg 3.3 before 3.3.1 allows remote attackers to cause a…

Fix: after 3.3
Fix from $1,950 2017-06-28
Ffmpeg HIGH 7.8
CVE-2017-9991

Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3…

Fix: after 2.8.11
Fix from $1,950 2017-06-28
Debian Linux HIGH 8.8
CVE-2017-9992

Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x bef…

Fix: 2.8.12 / 3.0.8+
Fix from $1,950 2017-06-28
Debian Linux HIGH 7.8
CVE-2017-9994

libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pi…

Fix: 2.8.12 / 3.0.8+
Fix from $1,950 2017-06-28
Ffmpeg HIGH 7.8
CVE-2017-9995

libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of ser…

Patch available
Fix from $1,950 2017-06-28
Ffmpeg HIGH 7.8
CVE-2017-9996

The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.…

Patch available
Fix from $1,950 2017-06-28
Data Server Client HIGH 7.1
CVE-2017-1105

IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a loc…

Patch available
Fix from $1,950 2017-06-27
Data Server Client HIGH 7.3
CVE-2017-1297

IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by…

Patch available
Fix from $1,950 2017-06-27
Freeware Advanced Audio Decoder 2 MEDIUM 5.5
CVE-2017-9219

The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2017-06-27