Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Firefox HIGH 8.8
CVE-2016-2818

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to …

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Firefox HIGH 8.8
CVE-2016-2815

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2485

libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX bu…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2484

libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX bu…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2483

The mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishan…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2482

The mm-video-v4l2 vdec component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishan…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2481

The mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishan…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2479

The mm-video-v4l2 vdec component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishan…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2476

mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX buffer sizes, which …

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 8.4
CVE-2016-2463

Multiple integer overflows in the h264dec component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.…

Mitigation only
Fix from $1,950 2016-06-13
Ip Phone 8800 Series Firmware HIGH 7.5
CVE-2016-1421

A vulnerability in the web application for Cisco IP Phones could allow an unauthenticated, remote attacker to execute code with root privileges or ca…

Mitigation only
Fix from $1,950 2016-06-10
Ubuntu Linux HIGH 7.5
CVE-2016-4447EPSS 14%

The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buff…

Fix: after 10.11.5
Fix from $1,950 2016-06-09
Debian Linux CRITICAL 9.8
CVE-2016-0749EPSS 8%

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code v…

Mitigation only
Fix from $2,300 2016-06-09
Debian Linux CRITICAL 9.8
CVE-2016-5108EPSS 25%

Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause …

Fix: after 2.2.3
Fix from $2,300 2016-06-08
Loadrunner CRITICAL 9.8
CVE-2016-4359EPSS 16%

Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 th…

Mitigation only
Fix from $2,300 2016-06-08
Email Security Appliance HIGH 7.5
CVE-2016-1405

libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-1…

Mitigation only
Fix from $1,950 2016-06-08
Debian Linux HIGH 8.8
CVE-2016-2335EPSS 10%

The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of servi…

No fix yet
Fix from $1,950 2016-06-07
Ubuntu Linux HIGH 7.1
CVE-2015-5261

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL com…

Mitigation only
Fix from $1,950 2016-06-07
Enterprise Linux Desktop HIGH 7.8
CVE-2015-5260

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash…

Mitigation only
Fix from $1,950 2016-06-07
Ubuntu Linux MEDIUM 6.5
CVE-2016-1702

The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval coun…

Fix: after 51.0.2704.63
Fix from $1,600 2016-06-05
Ubuntu Linux HIGH 7.5
CVE-2016-1691

Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-bas…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Ubuntu Linux MEDIUM 6.5
CVE-2016-1689

Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause …

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Ubuntu Linux MEDIUM 6.5
CVE-2016-1688

The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external s…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Chrome MEDIUM 6.5
CVE-2016-1686

The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Chrome MEDIUM 6.5
CVE-2016-1685

core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which allows remote attacker…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Ubuntu Linux HIGH 7.5
CVE-2016-1683

numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause …

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Debian Linux HIGH 8.8
CVE-2016-1681

Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, all…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Chrome HIGH 8.8
CVE-2016-1680

Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote attackers to cause…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Chrome HIGH 8.8
CVE-2016-1678

objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows …

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Imagemagick CRITICAL 9.8
CVE-2016-4564

The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to lo…

Fix: after 6.9.3-0
Fix from $2,300 2016-06-04