Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Mac Os X HIGH 7.8
CVE-2016-4723

Intel Graphics Driver in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (mem…

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Iphone Os MEDIUM 6.5
CVE-2016-4718

Buffer overflow in FontParser in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensi…

Fix: 3.0 / 10.0+
Fix from $1,600 2016-09-25
Mac Os X HIGH 7.8
CVE-2016-4703

Bluetooth in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corrupti…

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Iphone Os CRITICAL 9.8
CVE-2016-4702EPSS 6%

Audio in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a de…

Fix: 3.0 / 10.0+
Fix from $2,300 2016-09-25
Mac Os X HIGH 7.8
CVE-2016-4700

AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruptio…

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Mac Os X HIGH 7.8
CVE-2016-4699

AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruptio…

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Mac Os X HIGH 7.8
CVE-2016-4697

Apple HSSPI Support in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memor…

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Iphone Os CRITICAL 9.8
CVE-2016-4658EPSS 9%

xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does…

Fix: 2.9.5 / 3.0+
Fix from $2,300 2016-09-25
Safari HIGH 8.8
CVE-2016-4611

WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (m…

Fix: 10.0+
Fix from $1,950 2016-09-25
Firefox HIGH 8.8
CVE-2016-5278

Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird …

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox HIGH 8.8
CVE-2016-5275

Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to exe…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5270

Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5257

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow …

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Firefox CRITICAL 9.8
CVE-2016-5256

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory…

Fix: after 48.0.2
Fix from $2,300 2016-09-22
Usg2100 Firmware HIGH 7.5
CVE-2016-6669

Buffer overflow in the Authentication, Authorization and Accounting (AAA) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security ga…

Mitigation only
Fix from $1,950 2016-09-22
Debian Linux CRITICAL 9.8
CVE-2016-6525

Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (cra…

Fix: after 1.9
Fix from $2,300 2016-09-22
Vm Server HIGH 7.8
CVE-2016-3991

Heap-based buffer overflow in the loadImage function in the tiffcrop tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of s…

Fix: after 4.0.6
Fix from $1,950 2016-09-21
Libtiff HIGH 7.8
CVE-2016-3990

Heap-based buffer overflow in the horizontalDifference8 function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a de…

Fix: after 4.0.6
Fix from $1,950 2016-09-21
Debian Linux CRITICAL 9.8
CVE-2016-6354EPSS 9%

Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of servi…

Fix: after 2.6.0
Fix from $2,300 2016-09-21
Zookeeper HIGH 8.1
CVE-2016-5017EPSS 8%

Buffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax, allows attackers…

Fix: after 3.4.8
Fix from $1,950 2016-09-21
Enterprise Linux Desktop HIGH 7.8
CVE-2016-4302

Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to exe…

Fix: after 3.2.0
Fix from $1,950 2016-09-21
Libarchive HIGH 7.8
CVE-2016-4301

Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to…

Fix: after 3.2.0
Fix from $1,950 2016-09-21
Linux Enterprise Desktop MEDIUM 5.5
CVE-2015-8929

Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denia…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux HIGH 7.5
CVE-2015-8919

The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial …

Fix: after 3.1.901a
Fix from $1,950 2016-09-20
Suse Linux Enterprise Software Development Kit HIGH 7.5
CVE-2015-8918

The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a …

Fix: after 3.1.901a
Fix from $1,950 2016-09-20
Rslogix 500 Professional Edition HIGH 8.6
CVE-2016-5814

Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition, RSLogix 500 Standard Edition…

Patch available
Fix from $1,950 2016-09-19
Xcode HIGH 7.8
CVE-2016-4705

otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspec…

Fix: after 7.3.1
Fix from $1,950 2016-09-18
Xcode HIGH 7.8
CVE-2016-4704

otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspec…

Fix: after 7.3.1
Fix from $1,950 2016-09-18
PHP HIGH 7.5
CVE-2016-7418EPSS 11%

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service…

Fix: after 5.6.25
Fix from $1,950 2016-09-17
PHP HIGH 7.5
CVE-2016-7416EPSS 7%

ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale …

Fix: after 5.6.25
Fix from $1,950 2016-09-17