Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Libgd CRITICAL 9.8
CVE-2016-8670

Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.…

Fix: after 2.2.3
Fix from $2,300 2017-01-04
Tor HIGH 7.5
CVE-2016-8860

Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data had NUL termination, but the …

Fix: after 0.2.8.8
Fix from $1,950 2017-01-04
Libgd HIGH 7.5
CVE-2016-9933EPSS 7%

Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP befor…

Patch available
Fix from $1,950 2017-01-04
Libvncserver CRITICAL 9.8
CVE-2016-9941

Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (applicatio…

Fix: after 0.9.10
Fix from $2,300 2016-12-31
Libvncserver CRITICAL 9.8
CVE-2016-9942

Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application c…

Patch available
Fix from $2,300 2016-12-31
Qemu MEDIUM 6.5
CVE-2016-9846

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while updating th…

Fix: after 2.7.1
Fix from $1,600 2016-12-29
Workstation Player HIGH 7.8
CVE-2016-7081

Multiple heap-based buffer overflows in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when C…

Mitigation only
Fix from $1,950 2016-12-29
Workstation Player HIGH 7.8
CVE-2016-7082

VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is ena…

Mitigation only
Fix from $1,950 2016-12-29
Workstation Player HIGH 7.8
CVE-2016-7083

VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is ena…

No fix yet
Fix from $1,950 2016-12-29
Workstation Player HIGH 7.8
CVE-2016-7084

tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual p…

No fix yet
Fix from $1,950 2016-12-29
Fusion HIGH 8.8
CVE-2016-7461

The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x before 12.5.2 and VMware Fusion …

Mitigation only
Fix from $1,950 2016-12-29
Linux Kernel HIGH 7.8
CVE-2012-6704

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows lo…

Fix: 3.2.85 / 3.5+
Fix from $1,950 2016-12-28
Linux Kernel HIGH 7.8
CVE-2016-9793

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows…

Fix: 3.12.69 / 3.16.40+
Fix from $1,950 2016-12-28
Ffmpeg HIGH 7.8
CVE-2016-6671

The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attackers to cause a denial of service (memory corruption) or exe…

Fix: after 3.1.1
Fix from $1,950 2016-12-23
Ffmpeg MEDIUM 5.5
CVE-2016-7562

The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) v…

Fix: after 3.1.3
Fix from $1,600 2016-12-23
Edge HIGH 7.5
CVE-2016-7286EPSS 69%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

No fix yet
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7287EPSS 69%

The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of serv…

No fix yet
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7288EPSS 70%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

No fix yet
Fix from $1,950 2016-12-20
Publisher HIGH 7.8
CVE-2016-7289EPSS 25%

Microsoft Publisher 2010 SP2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted documen…

Mitigation only
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7296EPSS 17%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

Mitigation only
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7297EPSS 27%

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craft…

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.8
CVE-2016-7298EPSS 23%

Microsoft Office 2007 SP3, Office 2010 SP2, Word Viewer, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2016-12-20
Edge HIGH 7.5
CVE-2016-7181EPSS 14%

Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Micros…

No fix yet
Fix from $1,950 2016-12-20
Excel For Mac HIGH 7.8
CVE-2016-7263EPSS 19%

Microsoft Excel for Mac 2011 and Excel 2016 for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption)…

Mitigation only
Fix from $1,950 2016-12-20
Office CRITICAL 9.6
CVE-2016-7277EPSS 18%

Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka …

Mitigation only
Fix from $2,300 2016-12-20
Edge HIGH 7.5
CVE-2016-7279EPSS 15%

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory cor…

Mitigation only
Fix from $1,950 2016-12-20
Chrome HIGH 8.8
CVE-2016-5182

Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation in bitmap handling, wh…

Fix: after 53.0.2785.143
Fix from $1,950 2016-12-18
Gpu Driver HIGH 7.8
CVE-2016-8817

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a va…

Patch available
Fix from $1,950 2016-12-16
Gpu Driver HIGH 7.8
CVE-2016-8823

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where the size of an inpu…

Patch available
Fix from $1,950 2016-12-16
Gpu Driver HIGH 7.8
CVE-2016-8825

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where the …

Patch available
Fix from $1,950 2016-12-16