Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Podofo CRITICAL 9.8
CVE-2017-8378

Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of …

Patch available
Fix from $2,300 2017-05-01
Debian Linux HIGH 8.8
CVE-2017-8361

The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application cr…

Patch available
Fix from $1,950 2017-04-30
Rzip HIGH 7.8
CVE-2017-8364

The read_buf function in stream.c in rzip 2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash)…

No fix yet
Fix from $1,950 2017-04-30
Ettercap CRITICAL 9.8
CVE-2017-8366

The strescape function in ec_strings.c in Ettercap 0.8.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and applica…

No fix yet
Fix from $2,300 2017-04-30
Easy Avi\/divx\/xvid To Dvd Burner HIGH 7.8
CVE-2017-8367

Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Avi/Divx/Xvid to DVD Burner, Ea…

No fix yet
Fix from $1,950 2017-04-30
Panda Antivirus MEDIUM 5.5
CVE-2017-8339

PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoControl request to \\.\PSMEMDriv…

No fix yet
Fix from $1,600 2017-04-30
Libreoffice CRITICAL 9.8
CVE-2017-8358

LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/source/filter…

Fix: after 5.2.6
Fix from $2,300 2017-04-30
Imageworsener HIGH 8.8
CVE-2017-8325

The iw_process_cols_to_intermediate function in imagew-main.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a …

Fix: 1.3.1+
Fix from $1,950 2017-04-29
Privilege Manager For Unix CRITICAL 9.8
CVE-2017-6553EPSS 42%

Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server …

Fix: after 6.0.0-50
Fix from $2,300 2017-04-29
Hoozin Viewer HIGH 8.8
CVE-2017-2155

Buffer overflow in Hoozin Viewer 2, 3, 4.1.5.15 and earlier, 5.1.2.13 and earlier, and 6.0.3.09 and earlier allows remote attackers to execute arbitr…

Fix: after 6.0.3.09
Fix from $1,950 2017-04-28
Ts Ptcam\/poe Firmware HIGH 8.8
CVE-2017-2113

Buffer overflow in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 …

Fix: after 1.18
Fix from $1,950 2017-04-28
Wn G300r3 Firmware CRITICAL 9.8
CVE-2017-2142

Buffer overflow in WN-G300R3 firmware Ver.1.03 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: after 1.03
Fix from $2,300 2017-04-28
Linux Kernel CRITICAL 9.8
CVE-2017-7895EPSS 11%

The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attac…

Fix: 3.2.89 / 3.16.44+
Fix from $2,300 2017-04-28
Udfclient CRITICAL 9.8
CVE-2017-8305

The UDFclient (before 0.8.8) custom strlcpy implementation has a buffer overflow. UDFclient's strlcpy is used only on systems with a C library (e.g.,…

Fix: after 0.8.7
Fix from $2,300 2017-04-27
Riot CRITICAL 9.8
CVE-2017-8289

Stack-based buffer overflow in the ipv6_addr_from_str function in sys/net/network_layer/ipv6/addr/ipv6_addr_from_str.c in RIOT prior to 2017-04-25 al…

Fix: after 2017.01
Fix from $2,300 2017-04-27
Levi Studio Hmi Editor HIGH 8.8
CVE-2017-6035

A Stack-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulnerability causes a buffer over…

Fix: after 1.8.0
Fix from $1,950 2017-04-27
Levi Studio Hmi Editor HIGH 8.8
CVE-2017-6037

A Heap-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulnerability causes a buffer overf…

Fix: after 1.8.0
Fix from $1,950 2017-04-27
Freetype CRITICAL 9.8
CVE-2017-8287

FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in ps…

Fix: after 2.7.1
Fix from $2,300 2017-04-27
Privatetunnel HIGH 7.8
CVE-2017-7720

Buffer overflow in PrivateTunnel 2.7 and 2.8 allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other i…

No fix yet
Fix from $1,950 2017-04-26
Domino HIGH 8.8
CVE-2017-1274EPSS 7%

IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary…

No fix yet
Fix from $1,950 2017-04-25
Linux Kernel HIGH 7.0
CVE-2017-7477

Heap-based buffer overflow in drivers/net/macsec.c in the MACsec module in the Linux kernel through 4.10.12 allows attackers to cause a denial of ser…

Fix: 4.9.28 / 4.10.16+
Fix from $1,950 2017-04-25
Shield Tablet Firmware HIGH 7.8
CVE-2016-6915

Stack-based buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield…

Fix: after 4.3.0
Fix from $1,950 2017-04-24
Safari HIGH 8.8
CVE-2011-3438

WebKit, as used in Safari 5.0.6, allows remote attackers to cause a denial of service (process crash) or arbitrary code execution.

Mitigation only
Fix from $1,950 2017-04-24
Shield Tablet Firmware HIGH 7.8
CVE-2016-6917

Buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 b…

Fix: after 4.3.0
Fix from $1,950 2017-04-24
Pillow MEDIUM 5.5
CVE-2016-3076

Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memor…

Mitigation only
Fix from $1,600 2017-04-24
Northstar Controller MEDIUM 6.5
CVE-2017-2316

A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated…

Fix: after 2.1.0
Fix from $1,600 2017-04-24
Northstar Controller MEDIUM 6.5
CVE-2017-2325

A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated…

Fix: after 2.1.0
Fix from $1,600 2017-04-24
Linux Kernel HIGH 7.8
CVE-2007-6761

drivers/media/video/videobuf-vmalloc.c in the Linux kernel before 2.6.24 does not initialize videobuf_mapping data structures, which allows local use…

Fix: after 2.6.23
Fix from $1,950 2017-04-24
Chrome CRITICAL 9.8
CVE-2014-9654

The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.…

Fix: 55.1+
Fix from $2,300 2017-04-24
Bro HIGH 7.5
CVE-2015-1521

analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not properly handle zero values of a packet length, which allows remote attackers to cause a …

Fix: after 2.3.1
Fix from $1,950 2017-04-24