Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Edge HIGH 7.5
CVE-2016-0186EPSS 20%

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via…

Mitigation only
Fix from $1,950 2016-05-11
Office HIGH 7.8
CVE-2016-0140EPSS 17%

Microsoft Office 2007 SP3, Office 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attacke…

Mitigation only
Fix from $1,950 2016-05-11
Office HIGH 7.8
CVE-2016-0126EPSS 17%

Microsoft Office 2013 SP1, 2013 RT SP1, and 2016 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Offi…

Mitigation only
Fix from $1,950 2016-05-11
Android HIGH 8.8
CVE-2016-2439

Buffer overflow in btif/src/btif_dm.c in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 all…

Mitigation only
Fix from $1,950 2016-05-09
Android CRITICAL 9.8
CVE-2016-2429

libFLAC/stream_decoder.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not preve…

Mitigation only
Fix from $2,300 2016-05-09
Android CRITICAL 9.8
CVE-2016-2428

libAACdec/src/aacdec_drc.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not p…

Mitigation only
Fix from $2,300 2016-05-09
Fedora HIGH 7.8
CVE-2015-8868EPSS 8%

Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denia…

Mitigation only
Fix from $1,950 2016-05-06
Leap CRITICAL 9.8
CVE-2015-8863EPSS 7%

Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded nu…

Fix: after 1.5
Fix from $2,300 2016-05-06
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-2108EPSS 79%

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of serv…

Fix: after 1.0.1n
Fix from $2,300 2016-05-05
Wireshark MEDIUM 5.9
CVE-2016-4418

epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a de…

Mitigation only
Fix from $1,600 2016-05-01
Wireshark MEDIUM 5.9
CVE-2016-4417

Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allo…

Mitigation only
Fix from $1,600 2016-05-01
Wireshark MEDIUM 5.9
CVE-2016-4416

epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.2 mishandles the Grouping subfield, which allows remote a…

Mitigation only
Fix from $1,600 2016-05-01
Wireshark MEDIUM 5.9
CVE-2016-4415

wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 2.x before 2.0.2 incorrectly increases a certain octet count, which allows remote attac…

No fix yet
Fix from $1,600 2016-05-01
Firefox HIGH 8.8
CVE-2016-2814

Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ES…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox HIGH 7.5
CVE-2016-2808

The watch implementation in the JavaScript engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allo…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox HIGH 8.8
CVE-2016-2807EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before …

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Debian Linux HIGH 8.8
CVE-2016-2806EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to …

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Firefox HIGH 8.8
CVE-2016-2805EPSS 6%

Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory …

Mitigation only
Fix from $1,950 2016-04-30
Firefox HIGH 8.8
CVE-2016-2804EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 allow remote attackers to cause a denial of service (memory…

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Linux Kernel HIGH 8.4
CVE-2016-3134

The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cau…

Fix: after 4.5.2
Fix from $1,950 2016-04-27
Ubuntu Linux HIGH 8.1
CVE-2016-4054EPSS 77%

Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI…

Mitigation only
Fix from $1,950 2016-04-25
Ubuntu Linux HIGH 8.1
CVE-2016-4052EPSS 12%

Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execu…

Patch available
Fix from $1,950 2016-04-25
Ubuntu Linux HIGH 8.8
CVE-2016-4051EPSS 27%

Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or ex…

Patch available
Fix from $1,950 2016-04-25
Wireshark MEDIUM 5.9
CVE-2016-4082

epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses the wrong variable to inde…

Patch available
Fix from $1,600 2016-04-25
Wireshark MEDIUM 5.9
CVE-2016-4080

epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 misparses timestamp fields, which allow…

Mitigation only
Fix from $1,600 2016-04-25
Debian Linux MEDIUM 5.9
CVE-2016-4079

epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which …

Mitigation only
Fix from $1,600 2016-04-25
Wireshark MEDIUM 5.9
CVE-2016-4006

epan/proto.c in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not limit the protocol-tree depth, which allows remote attackers to cause…

Mitigation only
Fix from $1,600 2016-04-25
Foxit Reader HIGH 7.8
CVE-2016-4065

The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a de…

Fix: after 7.3.0.118
Fix from $1,950 2016-04-22
Opensuse MEDIUM 5.5
CVE-2016-3977

Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via …

Fix: after 5.1.2
Fix from $1,600 2016-04-21
Opensuse HIGH 7.5
CVE-2016-3190

The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (o…

Fix: after 1.12.16
Fix from $1,950 2016-04-21