Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
FreeBSD MEDIUM 6.2
CVE-2016-1885

Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p…

No fix yet
Fix from $1,600 2016-04-12
Debian Linux CRITICAL 9.8
CVE-2015-8710

The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds h…

Fix: 2.9.3+
Fix from $2,300 2016-04-11
Claws Mail HIGH 7.3
CVE-2015-8708

Stack-based buffer overflow in the conv_euctojis function in codeconv.c in Claws Mail 3.13.1 allows remote attackers to have unspecified impact via a…

Mitigation only
Fix from $1,950 2016-04-11
Claws Mail HIGH 7.3
CVE-2015-8614

Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail befor…

Fix: after 3.13.0
Fix from $1,950 2016-04-11
Debian Linux CRITICAL 9.8
CVE-2016-2385EPSS 27%

Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows r…

Fix: after 4.3.4
Fix from $2,300 2016-04-11
Debian Linux HIGH 7.5
CVE-2012-6700

The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of ser…

Patch available
Fix from $1,950 2016-04-11
Debian Linux HIGH 7.5
CVE-2012-6699

The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted respons…

Patch available
Fix from $1,950 2016-04-11
Debian Linux HIGH 7.5
CVE-2012-6698

The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted respon…

Patch available
Fix from $1,950 2016-04-11
Git CRITICAL 9.8
CVE-2016-2324EPSS 18%

Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which trigge…

Fix: after 2.7.3
Fix from $2,300 2016-04-08
Git CRITICAL 9.8
CVE-2016-2315EPSS 17%

revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename o…

Patch available
Fix from $2,300 2016-04-08
Debian Linux CRITICAL 9.8
CVE-2016-2851EPSS 21%

Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and ap…

Fix: after 4.1.0
Fix from $2,300 2016-04-07
Kitty CRITICAL 9.8
CVE-2016-2563EPSS 29%

Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a deni…

Fix: after 0.66.6.3
Fix from $2,300 2016-04-07
Fedora CRITICAL 9.8
CVE-2016-0729EPSS 9%

Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C be…

No fix yet
Fix from $2,300 2016-04-07
P8 Firmware HIGH 7.8
CVE-2015-8318

Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230…

Mitigation only
Fix from $1,950 2016-04-07
Mate S Firmware HIGH 7.8
CVE-2015-8319

Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230…

Mitigation only
Fix from $1,950 2016-04-07
Openstack HIGH 8.1
CVE-2016-1714EPSS 5%

The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulati…

Fix: after 2.3.0
Fix from $1,950 2016-04-07
Squid HIGH 7.5
CVE-2016-3948EPSS 36%

Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a cra…

Patch available
Fix from $1,950 2016-04-07
Ubuntu Linux HIGH 8.2
CVE-2016-3947EPSS 31%

Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remo…

Fix: after 3.5.15
Fix from $1,950 2016-04-07
Emc Powerscale Onefs HIGH 7.5
CVE-2015-6312

Cisco TelePresence Server 3.1 on 7010, Mobility Services Engine (MSE) 8710, Multiparty Media 310 and 320, and Virtual Machine (VM) devices allows rem…

Fix: 2.50 / 2017-01-06+
Fix from $1,950 2016-04-06
Eva Animator MEDIUM 6.3
CVE-2016-1176

Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page.

Mitigation only
Fix from $1,600 2016-04-05
Tivoli Storage Manager Fastback CRITICAL 9.8
CVE-2015-8522

Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code …

Mitigation only
Fix from $2,300 2016-04-05
Tivoli Storage Manager Fastback CRITICAL 9.8
CVE-2015-8521

Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code …

Mitigation only
Fix from $2,300 2016-04-05
Tivoli Storage Manager Fastback CRITICAL 9.8
CVE-2015-8520

Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code …

Mitigation only
Fix from $2,300 2016-04-05
Tivoli Storage Manager Fastback CRITICAL 9.8
CVE-2015-8519

Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code …

Mitigation only
Fix from $2,300 2016-04-05
PHP HIGH 8.2
CVE-2016-3142EPSS 6%

The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensiti…

Fix: after 10.11.4
Fix from $1,950 2016-03-31
PHP CRITICAL 9.8
CVE-2016-3141EPSS 38%

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial o…

Fix: after 10.11.4
Fix from $2,300 2016-03-31
Debian Linux HIGH 7.3
CVE-2015-8837EPSS 5%

Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (a…

Fix: after 20070708
Fix from $1,950 2016-03-30
Fedora HIGH 7.3
CVE-2015-8836

Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (applica…

Fix: after 20070708
Fix from $1,950 2016-03-30
Debian Linux HIGH 8.8
CVE-2016-1649

The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certai…

Fix: after 49.0.2623.95
Fix from $1,950 2016-03-29
Autodesk Backburner HIGH 7.5
CVE-2016-2344

Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to exe…

Fix: after 2016.0.0.2150
Fix from $1,950 2016-03-28