Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Edge HIGH 7.5
CVE-2017-0266EPSS 36%

A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory…

Patch available
Fix from $1,950 2017-05-12
Office HIGH 7.8
CVE-2017-0254EPSS 20%

Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Office for Mac 2011, Office for Mac 2016, Microsoft Office Web Ap…

Patch available
Fix from $1,950 2017-05-12
Edge HIGH 7.5
CVE-2017-0238EPSS 18%

A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript scripting engines handle objects in memory, aka "Scripting E…

Patch available
Fix from $1,950 2017-05-12
Edge HIGH 7.5
CVE-2017-0240EPSS 15%

A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory…

Patch available
Fix from $1,950 2017-05-12
Edge HIGH 7.5
CVE-2017-0221

A vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This CVE ID i…

Patch available
Fix from $1,950 2017-05-12
Edge HIGH 7.5
CVE-2017-0224EPSS 11%

A remote code execution vulnerability exists in the way JavaScript engines render when handling objects in memory in Microsoft Edge, aka "Scripting E…

Patch available
Fix from $1,950 2017-05-12
Edge HIGH 7.5
CVE-2017-0227EPSS 14%

A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory…

Patch available
Fix from $1,950 2017-05-12
Edge HIGH 7.5
CVE-2017-0228EPSS 17%

A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript engines render when handling objects in memory, aka "Scripti…

Patch available
Fix from $1,950 2017-05-12
Edge HIGH 7.5
CVE-2017-0229EPSS 11%

A remote code execution vulnerability exists in Microsoft Edge in the way JavaScript engines render when handling objects in memory, aka "Scripting E…

Patch available
Fix from $1,950 2017-05-12
Edge HIGH 7.5
CVE-2017-0230EPSS 11%

A remote code execution vulnerability exists in Microsoft Edge in the way JavaScript engines render when handling objects in memory, aka "Scripting E…

Patch available
Fix from $1,950 2017-05-12
Edge HIGH 7.5
CVE-2017-0234EPSS 38%

A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, …

Patch available
Fix from $1,950 2017-05-12
Edge HIGH 7.5
CVE-2017-0235EPSS 11%

A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, …

Patch available
Fix from $1,950 2017-05-12
Edge HIGH 7.5
CVE-2017-0236EPSS 32%

A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, …

Patch available
Fix from $1,950 2017-05-12
Miniupnpd CRITICAL 9.8
CVE-2017-8798EPSS 24%

Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspe…

No fix yet
Fix from $2,300 2017-05-11
Sapcar HIGH 7.8
CVE-2017-8852

SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted r…

No fix yet
Fix from $1,950 2017-05-10
Wolfssl HIGH 7.8
CVE-2017-8854

wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH parameters, aka a buffer overflow triggered by a malformed temporary…

Fix: after 3.10.0a
Fix from $1,950 2017-05-09
Vampset MEDIUM 5.5
CVE-2017-7967

All versions of VAMPSET software produced by Schneider Electric, prior to V2.2.189, are susceptible to a memory corruption vulnerability when a corru…

Fix: after 2.2.185
Fix from $1,600 2017-05-09
Forefront Security HIGH 7.8
CVE-2017-0290EPSS 77%

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Window…

Fix: after 1.1.13701.0
Fix from $1,950 2017-05-09
Smartdiag Diagnosis Tool HIGH 7.8
CVE-2017-6953

Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card" input fields. There may be …

Fix: after 2.5
Fix from $1,950 2017-05-08
Debian Linux HIGH 7.8
CVE-2017-8844

The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and a…

Patch available
Fix from $1,950 2017-05-08
Pcre2 CRITICAL 9.8
CVE-2017-8786

pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impac…

Patch available
Fix from $2,300 2017-05-05
Appspider Pro HIGH 7.5
CVE-2017-5240

Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malfo…

Fix: after 6.14.059
Fix from $1,950 2017-05-03
Gnulib CRITICAL 9.8
CVE-2017-7476

Gnulib before 2017-04-26 has a heap-based buffer overflow with the TZ environment variable. The error is in the save_abbr function in time_rz.c.

Fix: after 2017-04-25
Fix from $2,300 2017-05-02
Lame HIGH 7.8
CVE-2017-8419

LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of ser…

Fix: after 3.99.5
Fix from $1,950 2017-05-02
Binutils HIGH 7.5
CVE-2017-8397

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 and an invalid…

Patch available
Fix from $1,950 2017-05-01
Binutils HIGH 7.5
CVE-2017-8398

dwarf.c in GNU Binutils 2.28 is vulnerable to an invalid read of size 1 during dumping of debug information from a corrupt binary. This vulnerability…

Patch available
Fix from $1,950 2017-05-01
Pcre2 CRITICAL 9.8
CVE-2017-8399

PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures…

Fix: 10.30+
Fix from $2,300 2017-05-01
Libarchive MEDIUM 5.5
CVE-2016-10349

The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-rea…

Patch available
Fix from $1,600 2017-05-01
Libarchive MEDIUM 5.5
CVE-2016-10350

The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial o…

Patch available
Fix from $1,600 2017-05-01
Mad Libmad HIGH 7.8
CVE-2017-8373

The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer overflo…

No fix yet
Fix from $1,950 2017-05-01