Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Tcpdump CRITICAL 9.8
CVE-2016-7939

The GRE parser in tcpdump before 4.9.0 has a buffer overflow in print-gre.c, multiple functions.

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Tcpdump CRITICAL 9.8
CVE-2016-7940

The STP parser in tcpdump before 4.9.0 has a buffer overflow in print-stp.c, multiple functions.

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Tcpdump CRITICAL 9.8
CVE-2016-7973

The AppleTalk parser in tcpdump before 4.9.0 has a buffer overflow in print-atalk.c, multiple functions.

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Tcpdump CRITICAL 9.8
CVE-2016-7974

The IP parser in tcpdump before 4.9.0 has a buffer overflow in print-ip.c, multiple functions.

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Tcpdump CRITICAL 9.8
CVE-2016-7975

The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Tcpdump CRITICAL 9.8
CVE-2016-7983

The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Tcpdump CRITICAL 9.8
CVE-2016-7984

The TFTP parser in tcpdump before 4.9.0 has a buffer overflow in print-tftp.c:tftp_print().

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Tcpdump CRITICAL 9.8
CVE-2016-7985

The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print().

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Tcpdump CRITICAL 9.8
CVE-2016-7986

The GeoNetworking parser in tcpdump before 4.9.0 has a buffer overflow in print-geonet.c, multiple functions.

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Tcpdump CRITICAL 9.8
CVE-2016-7992

The Classical IP over ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-cip.c:cip_if_print().

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Tcpdump CRITICAL 9.8
CVE-2016-7993

A bug in util-print.c:relts_print() in tcpdump before 4.9.0 could cause a buffer overflow in multiple protocol parsers (DNS, DVMRP, HSRP, IGMP, light…

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Tcpdump CRITICAL 9.8
CVE-2016-8574

The FRF.15 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:frf15_print().

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9636EPSS 9%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27
Imagemagick MEDIUM 5.5
CVE-2016-9298

Heap overflow in the WaveletDenoiseImage function in MagickCore/fx.c in ImageMagick before 6.9.6-4 and 7.x before 7.0.3-6 allows remote attackers to …

Fix: after 6.9.6-3
Fix from $1,600 2017-01-27
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9634EPSS 9%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-9635EPSS 9%

Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote a…

Fix: after 1.10.1
Fix from $2,300 2017-01-27
Android CRITICAL 9.8
CVE-2016-8411

Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions that have qmi_qos_srvc.c. Android ID: 31805216. Ref…

Fix: after 7.1.1
Fix from $2,300 2017-01-27
Fbx Software Development Kit CRITICAL 9.8
CVE-2016-9303

Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code or cause an infinite loop condition whe…

Fix: after 2017.0
Fix from $2,300 2017-01-25
Fbx Software Development Kit HIGH 8.8
CVE-2016-9304

Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DF…

Fix: after 2017.0
Fix from $1,950 2017-01-25
Fbx Software Development Kit CRITICAL 9.8
CVE-2016-9306

Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DA…

Fix: after 2017.0
Fix from $2,300 2017-01-25
Fbx Software Development Kit CRITICAL 9.8
CVE-2016-9307

Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed 3D…

Fix: after 2017.0
Fix from $2,300 2017-01-25
Acrobat HIGH 7.8
CVE-2017-2970EPSS 7%

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability…

Fix: after 15.020.20042
Fix from $1,950 2017-01-24
Acrobat HIGH 7.8
CVE-2017-2971EPSS 9%

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability…

Fix: after 15.020.20042
Fix from $1,950 2017-01-24
Acrobat HIGH 7.8
CVE-2017-2972

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerabi…

Fix: after 15.020.20042
Fix from $1,950 2017-01-24
Quagga HIGH 7.5
CVE-2017-5495EPSS 19%

All versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, leading to a Denial-of-Service …

Fix: after 1.1.0
Fix from $1,950 2017-01-24
Ffmpeg HIGH 7.5
CVE-2016-6920

Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attackers to cause a denial of servi…

Fix: after 3.1.2
Fix from $1,950 2017-01-23
Openslp CRITICAL 9.8
CVE-2016-7567EPSS 12%

Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a cra…

Patch available
Fix from $2,300 2017-01-23
Landesk Management Suite CRITICAL 9.8
CVE-2016-3147EPSS 6%

Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of ser…

Fix: after 10.0.0.271
Fix from $2,300 2017-01-23
Pecl Http CRITICAL 9.8
CVE-2016-5873

Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable …

Fix: after 3.0.1
Fix from $2,300 2017-01-23
Chess CRITICAL 9.8
CVE-2015-8972

Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent a…

Fix: 6.2.4+
Fix from $2,300 2017-01-23