Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Freeware Advanced Audio Decoder 2 MEDIUM 5.5
CVE-2017-9220

The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2017-06-27
Skype HIGH 8.8
CVE-2017-9948EPSS 6%

A stack buffer overflow vulnerability has been discovered in Microsoft Skype 7.2, 7.35, and 7.36 before 7.37, involving MSFTEDIT.DLL mishandling of r…

Mitigation only
Fix from $1,950 2017-06-26
Libtiff MEDIUM 6.5
CVE-2017-9937

In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of servic…

Fix: after 4.0.8
Fix from $1,600 2017-06-26
Webex Advanced Recording Format Player HIGH 7.8
CVE-2017-6669

Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files. An attacker cou…

Mitigation only
Fix from $1,950 2017-06-26
Debian Linux MEDIUM 5.5
CVE-2017-9928

In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service vi…

Patch available
Fix from $1,600 2017-06-26
Debian Linux MEDIUM 5.5
CVE-2017-9929

In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service v…

Patch available
Fix from $1,600 2017-06-26
Lame MEDIUM 5.5
CVE-2015-9101

The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.98.4, 3.98.2, 3.98, 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4 and 3.99.5 allows remo…

No fix yet
Fix from $1,600 2017-06-25
Lame HIGH 7.8
CVE-2017-9871

The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a den…

Mitigation only
Fix from $1,950 2017-06-25
Lame HIGH 7.8
CVE-2017-9872EPSS 10%

The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to ca…

No fix yet
Fix from $1,950 2017-06-25
Debian Linux MEDIUM 6.5
CVE-2017-9775

Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) vi…

Fix: after 0.55.0
Fix from $1,600 2017-06-22
Solaris HIGH 7.8
CVE-2017-3629EPSS 5%

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 1…

Patch available
Fix from $1,950 2017-06-22
Solaris MEDIUM 5.3
CVE-2017-3631EPSS 6%

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Eas…

Patch available
Fix from $1,600 2017-06-22
Elastic Storage Server MEDIUM 6.2
CVE-2017-1304

IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing…

Mitigation only
Fix from $1,600 2017-06-21
Digital Editions CRITICAL 10.0
CVE-2017-3088EPSS 6%

Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF runtime engine. Successful exploitat…

Fix: after 4.5.4
Fix from $2,300 2017-06-20
Digital Editions CRITICAL 9.8
CVE-2017-3089EPSS 6%

Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF imaging model. Successful exploitati…

Fix: after 4.5.4
Fix from $2,300 2017-06-20
Digital Editions CRITICAL 9.8
CVE-2017-3093EPSS 6%

Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the bitmap representation module. Successful…

Fix: after 4.5.4
Fix from $2,300 2017-06-20
Digital Editions CRITICAL 9.8
CVE-2017-3094EPSS 6%

Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF processing engine. Successful exploi…

Fix: after 4.5.4
Fix from $2,300 2017-06-20
Digital Editions CRITICAL 9.8
CVE-2017-3095EPSS 6%

Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF parsing engine. Successful exploitat…

Mitigation only
Fix from $2,300 2017-06-20
Digital Editions CRITICAL 9.8
CVE-2017-3096EPSS 6%

Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the character code mapping module. Successfu…

Fix: after 4.5.4
Fix from $2,300 2017-06-20
HTTP Server CRITICAL 9.8
CVE-2017-7679EPSS 39%

In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Typ…

Fix: 2.2.33 / 2.4.26+
Fix from $2,300 2017-06-20
Linux Kernel HIGH 7.4
CVE-2017-1000364EPSS 5%

An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped…

Fix: after 4.11.5
Fix from $1,950 2017-06-19
Enterprise Linux HIGH 7.8
CVE-2017-1000366

glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially …

Patch available
Fix from $1,950 2017-06-19
Netbsd CRITICAL 9.8
CVE-2017-1000375EPSS 19%

NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate …

Fix: after 7.1
Fix from $2,300 2017-06-19
Enterprise Virtualization Server HIGH 7.0
CVE-2017-1000376

libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that lib…

Fix: 3.2+
Fix from $1,950 2017-06-19
Linux Kernel MEDIUM 5.9
CVE-2017-1000377

An issue was discovered in the size of the default stack guard page on PAX Linux (originally from GRSecurity but shipped by other Linux vendors), spe…

Mitigation only
Fix from $1,600 2017-06-19
Radare2 MEDIUM 5.5
CVE-2017-9761

The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and app…

Patch available
Fix from $1,600 2017-06-19
Radare2 HIGH 7.5
CVE-2017-9763

The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attacker…

Patch available
Fix from $1,950 2017-06-19
Binutils HIGH 7.8
CVE-2017-9742EPSS 8%

The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and app…

Patch available
Fix from $1,950 2017-06-19
Binutils HIGH 7.8
CVE-2017-9743

The print_insn_score32 function in opcodes/score7-dis.c:552 in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflo…

Patch available
Fix from $1,950 2017-06-19
Binutils HIGH 7.8
CVE-2017-9744

The sh_elf_set_mach_from_flags function in bfd/elf32-sh.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.…

Patch available
Fix from $1,950 2017-06-19