Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
PHP CRITICAL 9.8
CVE-2016-7134

ext/curl/interface.c in PHP 7.x before 7.0.10 does not work around a libcurl integer overflow, which allows remote attackers to cause a denial of ser…

Patch available
Fix from $2,300 2016-09-12
Android MEDIUM 5.5
CVE-2016-3881

The decoder_peek_si_internal function in vp9/vp9_dx_iface.c in libvpx in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.…

Patch available
Fix from $1,600 2016-09-11
Android HIGH 7.8
CVE-2016-3872

Buffer overflow in codecs/on2/dec/SoftVPX.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6…

Patch available
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3862

media/ExifInterface.java in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 does not prope…

Patch available
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3861EPSS 10%

LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions…

Patch available
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3858

Buffer overflow in drivers/soc/qcom/subsystem_restart.c in the Qualcomm subsystem driver in Android before 2016-09-05 on Nexus 5X and 6P devices allo…

Fix: after 7.0
Fix from $1,950 2016-09-11
Chrome HIGH 8.8
CVE-2016-5157

Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windo…

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Chrome HIGH 8.8
CVE-2016-5154

Multiple heap-based buffer overflows in PDFium, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, al…

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Debian Linux MEDIUM 5.9
CVE-2016-7179

Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 allows remot…

Patch available
Fix from $1,600 2016-09-09
Debian Linux MEDIUM 5.9
CVE-2016-7177

epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 does not restrict the number of channels, w…

Patch available
Fix from $1,600 2016-09-09
Wireshark MEDIUM 5.9
CVE-2016-7176

epan/dissectors/packet-h225.c in the H.225 dissector in Wireshark 2.x before 2.0.6 calls snprintf with one of its input buffers as the output buffer,…

Patch available
Fix from $1,600 2016-09-09
Nvrmini 2 HIGH 8.8
CVE-2016-5680EPSS 17%

Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authentic…

No fix yet
Fix from $1,950 2016-08-31
Mac Telnet CRITICAL 9.8
CVE-2016-7115

Buffer overflow in the handle_packet function in mactelnet.c in the client in MAC-Telnet 0.4.3 and earlier allows remote TELNET servers to execute ar…

Fix: after 0.4.3
Fix from $2,300 2016-08-30
Acrobat CRITICAL 9.8
CVE-2016-4270EPSS 6%

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.016.20045
Fix from $2,300 2016-08-26
Acrobat CRITICAL 9.8
CVE-2016-4269EPSS 6%

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.016.20045
Fix from $2,300 2016-08-26
Acrobat CRITICAL 9.8
CVE-2016-4268EPSS 6%

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.016.20045
Fix from $2,300 2016-08-26
Acrobat CRITICAL 9.8
CVE-2016-4267EPSS 6%

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.016.20045
Fix from $2,300 2016-08-26
Acrobat CRITICAL 9.8
CVE-2016-4266EPSS 6%

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.016.20045
Fix from $2,300 2016-08-26
Acrobat CRITICAL 9.8
CVE-2016-4265EPSS 6%

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.016.20045
Fix from $2,300 2016-08-26
Acrobat CRITICAL 9.8
CVE-2016-4119

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.016.20045
Fix from $2,300 2016-08-26
Dir 868l Firmware CRITICAL 9.8
CVE-2016-5681EPSS 12%

Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3…

Fix: after 3.00
Fix from $2,300 2016-08-25
Fortios CRITICAL 9.8
CVE-2016-6909EPSS 50%

Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 …

Fix: 4.1.11 / 4.2.13+
Fix from $2,300 2016-08-24
Aironet Access Point Software MEDIUM 6.5
CVE-2016-6363

The rate-limit feature in the 802.11 protocol implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x b…

Mitigation only
Fix from $1,600 2016-08-22
Debian Linux CRITICAL 9.1
CVE-2016-6254EPSS 6%

Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a…

Fix: 5.4.3 / 5.5.2+
Fix from $2,300 2016-08-19
Iphone Os HIGH 7.8
CVE-2016-4654

IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory…

Mitigation only
Fix from $1,950 2016-08-18
Debian Linux MEDIUM 6.5
CVE-2016-6207EPSS 6%

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers …

Fix: 5.5.38 / 5.6.24+
Fix from $1,600 2016-08-12
Linux CRITICAL 9.8
CVE-2016-5408

Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linu…

Patch available
Fix from $2,300 2016-08-10
Edge HIGH 7.5
CVE-2016-3322EPSS 14%

Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corrup…

Mitigation only
Fix from $1,950 2016-08-09
Office HIGH 7.8
CVE-2016-3318EPSS 22%

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allow remote attackers to execute arbitrary code via a crafted file, aka "Graphics Com…

Mitigation only
Fix from $1,950 2016-08-09
Office HIGH 7.8
CVE-2016-3317EPSS 22%

Microsoft Office 2010 SP2, Word 2007 SP3, Word 2010 SP2, Word for Mac 2011, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2016-08-09