Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Office HIGH 7.8
CVE-2016-3317EPSS 22%

Microsoft Office 2010 SP2, Word 2007 SP3, Word 2010 SP2, Word for Mac 2011, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2016-08-09
Word HIGH 7.8
CVE-2016-3316EPSS 47%

Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Offi…

No fix yet
Fix from $1,950 2016-08-09
Office HIGH 7.8
CVE-2016-3313EPSS 50%

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary …

No fix yet
Fix from $1,950 2016-08-09
Edge HIGH 7.5
CVE-2016-3296EPSS 15%

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Memory…

Mitigation only
Fix from $1,950 2016-08-09
Edge HIGH 7.5
CVE-2016-3293EPSS 15%

Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Mem…

Mitigation only
Fix from $1,950 2016-08-09
Edge HIGH 7.5
CVE-2016-3289EPSS 18%

Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corrup…

Mitigation only
Fix from $1,950 2016-08-09
Linux Kernel HIGH 7.8
CVE-2016-2063

Stack-based buffer overflow in the supply_lm_input_write function in drivers/thermal/supply_lm_core.c in the MSM Thermal driver for the Linux kernel …

Fix: after 3.19.8
Fix from $1,950 2016-08-07
Chrome CRITICAL 9.8
CVE-2016-5140

Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allo…

Fix: after 52.0.2743.82
Fix from $2,300 2016-08-07
Chrome HIGH 7.6
CVE-2016-5139

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow rem…

Mitigation only
Fix from $1,950 2016-08-07
Wireshark MEDIUM 5.9
CVE-2016-5359

epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allows remote attackers to cause a…

Patch available
Fix from $1,600 2016-08-07
Wireshark MEDIUM 5.9
CVE-2016-5356

wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, whi…

Patch available
Fix from $1,600 2016-08-07
Debian Linux CRITICAL 9.1
CVE-2016-5116

gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers …

Fix: after 2.2.1
Fix from $2,300 2016-08-07
Linux Kernel HIGH 7.4
CVE-2016-6516

Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service …

Fix: after 4.7
Fix from $1,950 2016-08-06
Linux Kernel HIGH 7.8
CVE-2016-6187

The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which allows local u…

Fix: 4.6.5+
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9882

Buffer overflow in drivers/media/radio/radio-iris.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices allows attacker…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9874

Buffer overflow in the Qualcomm components in Android before 2016-08-05 on Nexus 5, 5X, 6P, and 7 (2013) devices allows attackers to gain privileges …

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9871

Multiple buffer overflows in drivers/media/platform/msm/camera_v2/isp/msm_isp_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2016-3825

mm-video-v4l2/vidc/venc/src/omx_video_base.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allocates …

Patch available
Fix from $1,950 2016-08-05
Android HIGH 7.8
CVE-2016-3824

omx/OMXNodeInstance.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-…

Patch available
Fix from $1,950 2016-08-05
Android HIGH 7.8
CVE-2016-3823

The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, an…

Patch available
Fix from $1,950 2016-08-05
Debian Linux HIGH 7.8
CVE-2016-3822

exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08…

Patch available
Fix from $1,950 2016-08-05
Android CRITICAL 9.8
CVE-2016-3820

The ih264d decoder in mediaserver in Android 6.x before 2016-08-01 mishandles slice numbers, which allows remote attackers to execute arbitrary code …

Patch available
Fix from $2,300 2016-08-05
Android CRITICAL 9.8
CVE-2016-3819

Integer overflow in codecs/on2/h264dec/source/h264bsd_dpb.c in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x b…

Patch available
Fix from $2,300 2016-08-05
Android HIGH 7.3
CVE-2016-2497

services/core/java/com/android/server/pm/PackageManagerService.java in the framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x befo…

Patch available
Fix from $1,950 2016-08-05
Android CRITICAL 9.8
CVE-2014-9902

Buffer overflow in CORE/SYS/legacy/src/utils/src/dot11f.c in the Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices allows …

Fix: after 6.0.1
Fix from $2,300 2016-08-05
Linux HIGH 8.8
CVE-2016-5252

Stack-based buffer underflow in the mozilla::gfx::BasePoint4d function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote …

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox HIGH 8.8
CVE-2016-2838

Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows rem…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Firefox MEDIUM 6.3
CVE-2016-2837

Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox HIGH 8.8
CVE-2016-2836

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow remote attackers to …

Fix: after 47.0.1
Fix from $1,950 2016-08-05
International Components For Unicode CRITICAL 9.8
CVE-2016-6293

The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that…

Fix: after 57.1
Fix from $2,300 2016-07-25