Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Iphone Os CRITICAL 9.8
CVE-2015-7987

Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memory locations via vectors invo…

Fix: 2.1 / 7.6.7+
Fix from $2,300 2016-06-26
Webaccess MEDIUM 5.0
CVE-2016-4528

Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file.

Fix: after 8.1
Fix from $1,600 2016-06-25
Visilogic Oplc Ide CRITICAL 9.8
CVE-2016-4519

Stack-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.30 allows remote attackers to execute arbitrary code via a crafted filename f…

Fix: after 9.8.22
Fix from $2,300 2016-06-25
Asr 5000 Software HIGH 7.5
CVE-2016-1436

The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 …

Mitigation only
Fix from $1,950 2016-06-23
Mac Os X HIGH 7.8
CVE-2016-1861

The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a deni…

Fix: after 10.11.4
Fix from $1,950 2016-06-19
iOS MEDIUM 6.5
CVE-2016-1424

Cisco IOS 15.2(1)T1.11 and 15.2(2)TST allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun…

Mitigation only
Fix from $1,600 2016-06-19
Rv215w Wireless N Vpn Router Firmware MEDIUM 6.5
CVE-2016-1397

Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3…

Mitigation only
Fix from $1,600 2016-06-19
Debian Linux HIGH 8.8
CVE-2016-3062

The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (mem…

Fix: after 11.6
Fix from $1,950 2016-06-16
Dng Software Development Kit CRITICAL 9.8
CVE-2016-4167EPSS 5%

Adobe DNG Software Development Kit (SDK) before 1.4 2016 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) …

Fix: after 1.4.2012
Fix from $2,300 2016-06-16
Flash Player CRITICAL 9.8
CVE-2016-4163EPSS 6%

Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to…

Fix: after 21.0.0.241
Fix from $2,300 2016-06-16
Flash Player CRITICAL 9.8
CVE-2016-4162EPSS 6%

Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to…

Fix: after 21.0.0.241
Fix from $2,300 2016-06-16
Flash Player CRITICAL 9.8
CVE-2016-4160EPSS 6%

Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to…

Fix: after 21.0.0.241
Fix from $2,300 2016-06-16
Flash Player CRITICAL 9.8
CVE-2016-4161EPSS 6%

Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to…

Fix: after 21.0.0.241
Fix from $2,300 2016-06-16
Flash Player CRITICAL 9.8
CVE-2016-4120EPSS 6%

Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to…

Fix: after 21.0.0.241
Fix from $2,300 2016-06-16
Excel HIGH 7.3
CVE-2016-3233EPSS 15%

Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office doc…

Mitigation only
Fix from $1,950 2016-06-16
Edge HIGH 8.8
CVE-2016-3222EPSS 57%

Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Micros…

No fix yet
Fix from $1,950 2016-06-16
Edge HIGH 8.8
CVE-2016-3214EPSS 16%

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via…

Mitigation only
Fix from $1,950 2016-06-16
Jscript HIGH 7.5
CVE-2016-3207EPSS 17%

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attack…

Mitigation only
Fix from $1,950 2016-06-16
Jscript HIGH 7.5
CVE-2016-3206EPSS 15%

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attack…

Mitigation only
Fix from $1,950 2016-06-16
Jscript HIGH 7.5
CVE-2016-3205EPSS 15%

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attack…

Mitigation only
Fix from $1,950 2016-06-16
Chakra Javascript HIGH 7.5
CVE-2016-3202EPSS 17%

The Microsoft (1) Chakra JavaScript, (2) JScript, and (3) VBScript engines, as used in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, allo…

Mitigation only
Fix from $1,950 2016-06-16
Edge HIGH 8.8
CVE-2016-3199EPSS 27%

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via…

Mitigation only
Fix from $1,950 2016-06-16
Debian Linux HIGH 7.5
CVE-2016-4478

Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a …

Fix: after 7.2.6
Fix from $1,950 2016-06-13
Ubuntu Linux HIGH 7.5
CVE-2016-4356

The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds r…

Fix: after 1.3.2
Fix from $1,950 2016-06-13
Ubuntu Linux HIGH 7.5
CVE-2016-4355

Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data,…

Fix: after 1.3.2
Fix from $1,950 2016-06-13
Ubuntu Linux HIGH 7.5
CVE-2016-4354

ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via cra…

Fix: after 1.3.2
Fix from $1,950 2016-06-13
Fedora CRITICAL 9.1
CVE-2015-8869EPSS 5%

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive in…

Fix: after 4.02.3
Fix from $2,300 2016-06-13
Rse6500 Firmware HIGH 8.1
CVE-2016-5234

Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconferen…

Mitigation only
Fix from $1,950 2016-06-13
Firefox HIGH 8.8
CVE-2016-2824

The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to …

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox HIGH 8.8
CVE-2016-2819EPSS 24%

Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via fore…

Fix: after 46.0.1
Fix from $1,950 2016-06-13