Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Debian Linux CRITICAL 9.8
CVE-2016-2148EPSS 27%

Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involv…

Fix: after 1.24.2
Fix from $2,300 2017-02-09
Android HIGH 7.8
CVE-2017-0405

A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially crafted file to cause memory corruption during med…

Mitigation only
Fix from $1,950 2017-02-08
Android HIGH 7.8
CVE-2017-0406

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media …

Mitigation only
Fix from $1,950 2017-02-08
Android HIGH 7.8
CVE-2017-0407

A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media …

Mitigation only
Fix from $1,950 2017-02-08
Dhcpcd HIGH 7.5
CVE-2016-1504

dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length.

Fix: after 6.9.4
Fix from $1,950 2017-02-07
Debian Linux CRITICAL 9.8
CVE-2016-7446

Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. No…

Mitigation only
Fix from $2,300 2017-02-06
Debian Linux CRITICAL 9.8
CVE-2016-7447

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via u…

Fix: after 1.3.24
Fix from $2,300 2017-02-06
Debian Linux HIGH 7.5
CVE-2016-7800

Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of servic…

Fix: after 1.3.25
Fix from $1,950 2017-02-06
Linux Kernel MEDIUM 5.5
CVE-2016-10154

The smbhash function in fs/cifs/smbencrypt.c in the Linux kernel 4.9.x before 4.9.1 interacts incorrectly with the CONFIG_VMAP_STACK option, which al…

Patch available
Fix from $1,600 2017-02-06
Linux Kernel HIGH 7.8
CVE-2017-5547

drivers/hid/hid-corsair.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to…

Fix: 4.4.45 / 4.9.6+
Fix from $1,950 2017-02-06
Linux Kernel HIGH 7.8
CVE-2017-5548

drivers/net/ieee802154/atusb.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local use…

Patch available
Fix from $1,950 2017-02-06
Mcp Firmware MEDIUM 6.8
CVE-2015-4049

Unisys Libra 43xx, 63xx, and 83xx, and FS600 class systems with MCP-FIRMWARE 40.0 before 40.0IC4 Build 270 might allow remote authenticated users to …

Mitigation only
Fix from $1,600 2017-02-03
Fedora MEDIUM 5.5
CVE-2016-4796

Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (…

Fix: after 2.1.0
Fix from $1,600 2017-02-03
Debian Linux MEDIUM 5.5
CVE-2016-2317

Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the…

Mitigation only
Fix from $1,600 2017-02-03
Ios Xe MEDIUM 6.8
CVE-2017-3824

A vulnerability in the handling of list headers in Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, remote attacker to ca…

Mitigation only
Fix from $1,600 2017-02-03
General Parallel File System HIGH 7.2
CVE-2016-6115

IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary co…

Patch available
Fix from $1,950 2017-02-01
Tivoli Storage Manager HIGH 7.8
CVE-2016-5985

The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based Backup is enabled. A local att…

Fix: after 7.1.6.2
Fix from $1,950 2017-02-01
Security Appscan HIGH 7.3
CVE-2016-6042

IBM AppScan Enterprise Edition could allow a remote attacker to execute arbitrary code on the system, caused by improper handling of objects in memor…

Patch available
Fix from $1,950 2017-02-01
Expressway HIGH 8.6
CVE-2017-3790

A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow…

Mitigation only
Fix from $1,950 2017-02-01
Libxpm CRITICAL 9.8
CVE-2016-10164EPSS 8%

Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to ca…

Fix: after 3.5.11
Fix from $2,300 2017-02-01
Activetouch General Plugin Container HIGH 8.8
CVE-2017-3823EPSS 27%

An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Fi…

Fix: after 10031.6.2017.0125
Fix from $1,950 2017-02-01
Potrace MEDIUM 5.5
CVE-2016-8685

The findnext function in decompose.c in potrace 1.13 allows remote attackers to cause a denial of service (invalid memory access and crash) via a cra…

Fix: after 1.12
Fix from $1,600 2017-01-31
Potrace HIGH 7.8
CVE-2016-8686

The bm_new function in bitmap.h in potrace 1.13 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory alloc…

Fix: after 1.12
Fix from $1,950 2017-01-31
Potrace HIGH 7.8
CVE-2016-8698

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact v…

Fix: after 1.12
Fix from $1,950 2017-01-31
Potrace HIGH 7.8
CVE-2016-8699

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact v…

Fix: after 1.12
Fix from $1,950 2017-01-31
Potrace HIGH 7.8
CVE-2016-8700

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact v…

Fix: after 1.12
Fix from $1,950 2017-01-31
Potrace HIGH 7.8
CVE-2016-8701

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact v…

Fix: after 1.12
Fix from $1,950 2017-01-31
Potrace HIGH 7.8
CVE-2016-8702

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact v…

Fix: after 1.12
Fix from $1,950 2017-01-31
Potrace HIGH 7.8
CVE-2016-8703

Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact v…

Fix: after 1.12
Fix from $1,950 2017-01-31
Webmail HIGH 8.8
CVE-2015-2181

Multiple buffer overflows in the DBMail driver in the Password plugin in Roundcube before 1.1.0 allow remote attackers to have unspecified impact via…

Fix: 1.1.0+
Fix from $1,950 2017-01-30